Concept and mechanism
External-contributor data should remain data. Interpolating PR titles directly into script text can enable injection before the shell executes; passing values through env and using quoted expansion without eval reduces that surface. Downloaded code deserves the same analysis: pull_request_target can have a privileged context, but the external head remains untrusted. OIDC avoids the need for certain persistent credentials without making arbitrary code execution with production access safe. Id-token: write allows obtaining a token; the cloud trust policy decides which identities, audiences, and contexts may exchange it for effective access. Temporary credentials still require careful scoping while valid.
Guided application
In a fictional promotion, validate digest and producer identity against policy before trusting an attestation. Provenance does not prove absence of vulnerabilities or replace operational approval. Serialize deployments changing the same destination and define pending-run handling: single mode replaces the previous pending run; queue: max permits a bounded queue and cannot combine with cancel-in-progress: true. Ordering considers entry into group waiting rather than initial dispatch order. Canceling a job does not reverse transactions already executed. To optimize costs, use suitable dependency caching and retention while preserving validation and excluding credentials. Record actual state after failure before deciding rollback or continuation.
A runs, B waits, C arrives in single mode: B is replaced; without cancel-in-progress, A continues.
Common pitfalls
OIDC as universal trust; attestation as safe software; cancellation as rollback; queue as dispatch order.
Related topics: Events, filters, and dependencies · Data, outputs, and service networking · Reuse, artifacts, and troubleshooting
Promote only identified content with validated origin, suitable authorization, and defined recovery.
Reference: Secure use of Actions · GH-200 skills measured January2026;study guide updated2026-02-05