Workflow Execution Protections: Actor and Event Configuration [Public Preview]
- 主要语言
- 没有语言数据
- 星标
- 8.9k
- 派生
- 1.8k
- PR 合并指标
- 30 天内没有已合并 PR
描述
### Value Prop
Workflow execution protections give administrators precise control over which GitHub Actions workflows can run, based on who triggers them and what event starts them. This helps teams prevent unauthorized or unexpected workflow runs, making it easier to safeguard sensitive information and maintain build integrity across all projects.
### Expected Outcome
By introducing these protections, organizations can strengthen their security posture and reduce the risk of supply chain attacks or insider threats. Applying consistent, centralized rules for workflow triggers helps teams scale their governance, ensuring only trusted actors and events can execute workflows across repositories.
贡献指南
调研方向
该 issue 描述了基于参与者和触发事件的工作流执行保护,但没有指明文件、测试或实现入口。首先审查所述的价值主张和预期结果;要完成此项工作,需要为这些保护措施定义实现范围和可验证的行为。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- github-actions
- 领域
- devops, security
- Issue 类型
- 功能
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 冷清
- 描述清晰度
- 需要澄清
- 新手友好度
- 20/100