/securing-github-actions-workflows
Harden GitHub Actions workflows against supply chain abuse, token misuse, and unsafe workf.
Harden GitHub Actions workflows against supply chain abuse, token misuse, and unsafe workflow execution patterns through enforceable CI security controls.
Category
Security
Execution
8 steps, sequential + gated
Goal
Harden GitHub Actions workflows against supply chain abuse, token misuse, and unsafe workflow execution patterns through enforceable CI security controls.
Scope
Applies to
- +Secure GitHub Actions workflows
- +Enforce SHA pinning and least-privilege workflow permissions
- +Harden pull_request and pull_request_target behavior
Does not cover
- −Trivial changes outside the workflow domain
Triggers
"Secure GitHub Actions workflows""Enforce SHA pinning and least-privilege workflow permissions""Harden pull_request and pull_request_target behavior""Add workflow change controls and secret handling safeguards"
Inputs
- →Context: environment/system affected
- →Scope: change boundary
- →Constraints: policy or hard rules
Invariants
- 01Third-party actions must be pinned to immutable SHAs.
- 02`GITHUB_TOKEN` permissions default to least privilege.
- 03Untrusted input must never be directly interpolated into shell commands.
- 04Workflow changes require explicit ownership/review controls.
- 05Secrets exposure paths are blocked and auditable.
Procedure
- Step 1Step 1 — **Inventory and baseline**
- Step 2Step 2 — **Enforce action integrity**
- Step 3Step 3 — **Minimize token privileges**
- Step 4Step 4 — **Harden untrusted input handling**
- Step 5Step 5 — **Secure fork/PR execution model**
- Step 6Step 6 — **Protect secrets and environments**
- Step 7Step 7 — **Apply change governance**
- Step 8Step 8 — **Validate and monitor**
Outputs
- ▸Hardened workflow definitions with pinned actions and scoped permissions.
- ▸Workflow security audit report with findings and remediation status.
- ▸Governance controls for workflow path changes (owner/reviewer policy).
- ▸Exception register for temporary deviations.
Review Gate
- [ ]All third-party actions are SHA-pinned.
- [ ]Workflow/job token permissions follow least-privilege model.
- [ ]No unsafe untrusted-input interpolation paths remain.
- [ ]Secret handling and environment protection controls are enforced.
- [ ]Workflow change governance and approval controls are active.