<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CodeQL on PlumePHP</title><link>https://plumephp.com/tags/codeql/</link><description>Recent content in CodeQL on PlumePHP</description><generator>Hugo</generator><language>zh-CN</language><lastBuildDate>Wed, 30 Sep 2026 10:00:00 +0800</lastBuildDate><atom:link href="https://plumephp.com/tags/codeql/index.xml" rel="self" type="application/rss+xml"/><item><title>GitHub Actions 依赖安全：Dependabot、SBOM 与供应链防护</title><link>https://plumephp.com/github-actions-dependabot-dependency-security/</link><pubDate>Wed, 30 Sep 2026 10:00:00 +0800</pubDate><guid>https://plumephp.com/github-actions-dependabot-dependency-security/</guid><description>&lt;blockquote&gt;
&lt;p&gt;软件供应链攻击是 2020 年代最严峻的安全威胁之一——从 npm 包被植入恶意代码到 GitHub Action 被篡改，一条依赖链上的薄弱环节可能让整个组织暴露。GitHub 提供了一整套工具来防护依赖安全：Dependabot 自动监控漏洞、SBOM 追踪依赖全景、CodeQL 深度代码分析、密钥扫描防止泄露。本文从配置到集成，构建完整的依赖安全防线。&lt;/p&gt;</description></item></channel></rss>