One GitHub Issue, Production Credentials: The Claude Code Action Injection Chain
Two separate disclosures against Anthropic’s Claude Code GitHub Action show how a single opened issue can walk out with OIDC tokens and an unscrubbed API key. Neither got a CVE, which is its own problem.