Github Actions Security

Harden GitHub Actions workflows against the well-known footguns. Covers SHA-pinned third-party actions, scoped GITHUB_TOKEN permissions, OIDC in place of long-lived cloud credentials, the pull_request_target trap, untrusted-input interpolation, and protected deploy environments. Invoke when adding a new workflow, introducing a third-party action, or migrating from long-lived secrets to OIDC.

yanacuti1121 28269cd 10.7 KB Updated 2 repo stars

File contents

yanacuti1121/Yana-AI/tree/main/core/skills/gw360--github-actions-security commit 28269cd7e4

Frequently asked questions

npx skillmds add yanacuti1121/github-actions-security