Skip to content

Securing GitHub Actions in the Enterprise

A practical examination of the supply-chain, execution, identity and governance risks created by GitHub Actions—and how enterprises can control them without destroying developer agility.

In progress · 3 parts published

  1. Securing GitHub Actions in the Enterprise · Part 1

    Securing GitHub Actions Is a Hard Problem

    10 min read

    Why securing GitHub Actions demands control of code, events, identities, and execution.

  2. Securing GitHub Actions in the Enterprise · Part 2

    Every GitHub Action is a Supply Chain Decision

    11 min read

    How each GitHub Action extends your supply chain through trust, dependencies, and privilege.

  3. Securing GitHub Actions in the Enterprise · Part 3

    Why Pinning GitHub Actions Is Necessary — but Not Sufficient

    Updated:
    11 min read

    Pinning GitHub Actions prevents silent changes, but does not guarantee reproducible execution.