CVE-2026-45793: Anatomy of a 14-Hour PHP Supply-Chain Near-Miss
A detailed analysis of a recent critical security vulnerability that nearly caused a massive supply-chain attack in the PHP ecosystem, affecting GitHub Actions workflows for ~14 hours. The discussion reveals how GITHUB_TOKENs were accidentally logged publicly, potentially exposing thousands of repositories to malicious attacks.