github-actions-security

SKILLWorkflowcommunauté
v0.0.0GoldenWing-360MITMis à jour il y a 18 jSource →

Harden GitHub Actions workflows against the well-known footguns. Covers SHA-pinned third-party actions, scoped GITHUB_TOKEN permissions, OIDC in place of long-lived cloud credentials, the pull_request_target trap, untrusted-input interpolation, and protected deploy environments. Invoke when adding a

Community-submitted skill. Not yet reviewed by the Forge team. Full prompt content may not be available.Request review →
15Étoiles du dépôt
1Clients
1Formats
il y a 18 jDernière mise à jour
Skill
AuteurGoldenWing-360
Version0.0.0
LicenceMIT
CatégorieWorkflow
Formatsskill.md
PromptNon publié
Compatibilité
Claude✓ Pris en charge
Cursor
Copilot
ChatGPT
Gemini
À propos

Harden GitHub Actions workflows against the well-known footguns. Covers SHA-pinned third-party actions, scoped GITHUB_TOKEN permissions, OIDC in place of long-lived cloud credentials, the pull_request_target trap, untrusted-input interpolation, and protected deploy environments. Invoke when adding a new workflow, introducing a third-party action, or migrating from long-lived secrets to OIDC.

Mots-clés
skillclaude