DEV Community

Yuri-Ryabkov
Yuri-Ryabkov

Posted on

1

Secure your Github Workflow

TL;DR

Specify commit SHA when setting workflow with Github Actions.

body

GitHub Actions on GitHub Marketplace is not security checked even official one, therefore developers who write workflow should make sure action safe and describe its commit version SHA from a security perspective.

Otherwise tokens you provided malicious action might be used for mining virtual currency. If you have described actions on yaml according to official description, check that is not specified with tag or branch.

Top comments (0)

AWS Q Developer image

Your AI Code Assistant

Automate your code reviews. Catch bugs before your coworkers. Fix security issues in your code. Built to handle large projects, Amazon Q Developer works alongside you from idea to production code.

Get started free in your IDE

👋 Kindness is contagious

DEV shines when you're signed in, unlocking a customized experience with features like dark mode!

Okay