5 ms·
https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions https://docs.github.com/en/actions/security-guides/security-... Probab
by staticassertion 5y ago
https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions https://docs.github.com/en/actions/security-guides/security-...
Probably worth checking out this guide. GHA can be a pretty scary thing.
- jshier 5y agoNone of that is scary. Pretty much all of that advice applies to systems you run internally. I do wish GHA had a solution for secure file injection, which solutions like Jenkins already have, so we didn't need a janky workaround for JSON blobs.