3 ms·
Do you do this for public repos? GitHub Actions is strongly not recommended for non-private. Struggling to have good security policies in place for a deployment
by leonheld 3y ago
Do you do this for public repos? GitHub Actions is strongly not recommended for non-private. Struggling to have good security policies in place for a deployment I'm doing...
- bmitc 3y ago> GitHub Actions is strongly not recommended for non-private. By who? Why?
- akerl_ 3y agoWhere are you seeing that GitHub actions isn’t recommended for public repos?
- theodorton 3y agoI believe they're referring to this section: https://docs.github.com/en/actions/hosting-your-own-runners/managing-self-hosted-runners/about-self-hosted-runners#self-hosted-runner-security https://docs.github.com/en/actions/hosting-your-own-runners/...
- Belphemur 3y agoSounds like outdated advice from the time before they implemented approval for running action from PR of untrusted people. In the past, people could modify the GitHub action workflow and run crypto miners on the agents. But since GitHub changed the default for PR where the actions aren't run anymore that killed that attack vector.
- everfrustrated 3y agoBecause the self-hosted runners save state between runs, as well as publicly-opened PRs/branches giving the public access to your runner environment variables/secrets.
- justinclift 3y agoThanks, I'd not seen that recommendation. Looks like I'd better do some research. :)