Skip to content
Forged Damien Murphy

Securing GitHub Actions in the Enterprise

A practical examination of the supply-chain, execution, identity and governance risks created by GitHub Actions—and how enterprises can control them without destroying developer agility.

In progress · 1 part published

  1. Securing GitHub Actions in the Enterprise · Part 1

    Securing GitHub Actions Is a Hard Problem

    10 min read

    GitHub Actions combines third-party executable code, privileged CI/CD environments and complex event-driven behaviour. Securing it requires far more than pinning versions or restricting the Marketplace.