github-actions-security

SKILLFlujo de trabajocomunidad
v0.0.0GoldenWing-360MITActualizado hace 2 mFuente →

Harden GitHub Actions workflows against the well-known footguns. Covers SHA-pinned third-party actions, scoped GITHUB_TOKEN permissions, OIDC in place of long-lived cloud credentials, the pull_request_target trap, untrusted-input interpolation, and protected deploy environments. Invoke when adding a

Community-submitted skill. Not yet reviewed by the Forge team. Full prompt content may not be available.Request review →
15Estrellas del repo
1Clientes
1Formatos
hace 2 mÚltima actualización
Skill
AutorGoldenWing-360
Versión0.0.0
LicenciaMIT
CategoríaFlujo de trabajo
Formatosskill.md
PromptNo publicado
Compatibilidad
Claude✓ Compatible
Cursor—
Copilot—
ChatGPT—
Gemini—
Acerca de

Harden GitHub Actions workflows against the well-known footguns. Covers SHA-pinned third-party actions, scoped GITHUB_TOKEN permissions, OIDC in place of long-lived cloud credentials, the pull_request_target trap, untrusted-input interpolation, and protected deploy environments. Invoke when adding a new workflow, introducing a third-party action, or migrating from long-lived secrets to OIDC.

Palabras clave
skillclaude

Sin cobertura de dependencias

Esta entrada no publica ningún paquete de npm, así que Forge no tiene un árbol de dependencias para ella. Es una carencia de cobertura, no una afirmación de que no tenga dependencias.

Temas

Relacionados en security