github / github/roadmap

Workflow Execution Protections: Actor and Event Configuration [Public Preview]

未关闭
#1,259 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
cloud Enterprise Free Shipped Team
主要语言
没有语言数据
星标
8.9k
派生
1.8k
PR 合并指标
30 天内没有已合并 PR

描述

### Value Prop

Workflow execution protections give administrators precise control over which GitHub Actions workflows can run, based on who triggers them and what event starts them. This helps teams prevent unauthorized or unexpected workflow runs, making it easier to safeguard sensitive information and maintain build integrity across all projects.

### Expected Outcome

By introducing these protections, organizations can strengthen their security posture and reduce the risk of supply chain attacks or insider threats. Applying consistent, centralized rules for workflow triggers helps teams scale their governance, ensuring only trusted actors and events can execute workflows across repositories.

贡献指南

打开贡献指南

调研方向

该 issue 描述了基于参与者和触发事件的工作流执行保护,但没有指明文件、测试或实现入口。首先审查所述的价值主张和预期结果;要完成此项工作,需要为这些保护措施定义实现范围和可验证的行为。

由索引模型根据 Issue 内容生成。

评估

技术栈
github-actions
领域
devops, security
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
冷清
描述清晰度
需要澄清
新手友好度
20/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。