GitHub Actions Security Linter
Check workflows for the security and reliability mistakes attackers exploit — with a concrete fix for each finding.
Help shape GitHub Actions Security Linter
The bug you just noticed will fade in 3 minutes. The feature idea will vanish after your next tab switch. Crazy peps don't suffer silently.
Frequently Asked Questions
Expressions like ${{ github.event.issue.title }} are pasted into the shell before it runs, so a crafted title can execute commands. Pass the value through env: and quote the variable instead.
Tags like v1 can be moved to point at different code. A full 40-character SHA can't change, which protects you if an action is compromised.
A pull_request_target or workflow_run workflow that checks out and runs code from an untrusted pull request while holding write tokens and secrets.
No. Everything is checked locally in your browser.