← GitHub Actions: automation, security, and operations
07 / 7 · 50 MIN

Security, provenance, and promotion

Keep untrusted code separate from production authorization.

Concept and mechanism

External-contributor data should remain data. Interpolating PR titles directly into script text can enable injection before the shell executes; passing values through env and using quoted expansion without eval reduces that surface. Downloaded code deserves the same analysis: pull_request_target can have a privileged context, but the external head remains untrusted. OIDC avoids the need for certain persistent credentials without making arbitrary code execution with production access safe. Id-token: write allows obtaining a token; the cloud trust policy decides which identities, audiences, and contexts may exchange it for effective access. Temporary credentials still require careful scoping while valid.

Guided application

In a fictional promotion, validate digest and producer identity against policy before trusting an attestation. Provenance does not prove absence of vulnerabilities or replace operational approval. Serialize deployments changing the same destination and define pending-run handling: single mode replaces the previous pending run; queue: max permits a bounded queue and cannot combine with cancel-in-progress: true. Ordering considers entry into group waiting rather than initial dispatch order. Canceling a job does not reverse transactions already executed. To optimize costs, use suitable dependency caching and retention while preserving validation and excluding credentials. Record actual state after failure before deciding rollback or continuation.

IN PRACTICE

A runs, B waits, C arrives in single mode: B is replaced; without cancel-in-progress, A continues.

Common pitfalls

OIDC as universal trust; attestation as safe software; cancellation as rollback; queue as dispatch order.

Related topics: Events, filters, and dependencies · Data, outputs, and service networking · Reuse, artifacts, and troubleshooting

Take this idea with you

Promote only identified content with validated origin, suitable authorization, and defined recovery.

Create account

Reference: Secure use of Actions · GH-200 skills measured January2026;study guide updated2026-02-05