A public Docker image can briefly publish its GitHub Actions workflow identity.
GitHub Actions workflows that use actions/checkout v2–v5 with persisted credentials and publish Docker images whose build context includes the checkout's .git directory.
actions/checkout v2 through v5 stored the token in .git/config. A broad Docker COPY could preserve it in an image layer published while the token was still live, allowing a fast puller to use the workflow’s repository permissions.
Detail and 4 sources
The reported scan found more than 240,000 exposed tokens, but it did not say how many remained usable when discovered. Version 6 moves the credential to RUNNER_TEMP and closes this copy path for updated jobs.