Supply Chain Hardened CI CD

Hardened GitHub Actions release workflow patterns for supply-chain security. Use when reviewing or writing GitHub Actions release workflows (.github/workflows/*.yml). Contains SHA-pinning, OIDC trusted publishing, two-job build/publish split, --ignore-scripts, Pwn Request prevention, deny-by-default permissions, and egress hardening patterns. Triggered by March 2026 TeamPCP campaign that specifically hijacked release tags.

uw-ssec 871d44b 3.5 KB Updated

File contents

uw-ssec/rse-plugins/tree/main/plugins/supply-chain-security/skills/supply-chain-hardened-ci-cd commit 871d44b603

Frequently asked questions

npx skillmds@latest add uw-ssec/supply-chain-hardened-ci-cd