github-actions-hardening
Use when writing, reviewing, or hardening GitHub Actions workflows (.github/workflows/*.yml): script injection, pull_request_target/workflow_run escalation, SHA pinning, least-privilege GITHUB_TOKEN, secret exposure, OIDC, and self-hosted runners.
Pinned to revision a3bdfb828b57, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/github-actions-hardening/SKILL.md
- skills/github-actions-hardening/references/injection.md
- skills/github-actions-hardening/references/permissions-and-tokens.md
- skills/github-actions-hardening/references/report-format.md
- skills/github-actions-hardening/references/supply-chain.md
- skills/github-actions-hardening/references/triggers-and-privilege.md
Every link opens the file at its source, pinned to the revision this page describes.