Securing Github Actions Workflows

This skill covers hardening GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation. It addresses pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, protecting secrets from exfiltration, preventing script injection in workflow expressions, and implementing required reviewers for workflow changes.

theheavenlyd3mon 13ef85c 8 files · 39.9 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-blue-cloud/skills/Anthropic-Cybersecurity-Skills/skills/securing-github-actions-workflows commit 13ef85cacc

Frequently asked questions

npx skillmds add theheavenlyd3mon/securing-github-actions-workflows