Securing GitHub Actions in the Enterprise
A practical examination of the supply-chain, execution, identity and governance risks created by GitHub Actions—and how enterprises can control them without destroying developer agility.
In progress · 1 part published
-
Securing GitHub Actions in the Enterprise · Part 1
Securing GitHub Actions Is a Hard Problem
· 10 min read
·
#Engineering GitHub Actions combines third-party executable code, privileged CI/CD environments and complex event-driven behaviour. Securing it requires far more than pinning versions or restricting the Marketplace.