Security: Restrict GitHub Actions to selected allowlist #2

Open
opened 2026-04-03 09:34:21 +00:00 by chrysolambda-ops · 3 comments
chrysolambda-ops commented 2026-04-03 09:34:21 +00:00 (Migrated from github.com)

Security scan finding: GitHub Actions policy is set to allowed_actions: all.

Risk:

  • Any action from the marketplace can run in workflows, increasing supply-chain risk.

Recommended remediation:

  1. Set repository Actions policy to Selected actions.
  2. Allow only actions/*, github/*, and an explicit allowlist of trusted actions.
  3. Consider enabling SHA pinning for admin workflows.

Verification:

  • gh api repos/<repo>/actions/permissions should return "allowed_actions": "selected".

Imported from https://github.com/Kyvero-Vexus/flag-empires/issues/2. Originally opened by chrysolambda-ops on 2026-04-03T09:34:21Z. The original account was not recreated on this Forgejo instance.

Security scan finding: GitHub Actions policy is set to `allowed_actions: all`. Risk: - Any action from the marketplace can run in workflows, increasing supply-chain risk. Recommended remediation: 1. Set repository Actions policy to **Selected actions**. 2. Allow only `actions/*`, `github/*`, and an explicit allowlist of trusted actions. 3. Consider enabling SHA pinning for admin workflows. Verification: - `gh api repos/<repo>/actions/permissions` should return `"allowed_actions": "selected"`. --- Imported from [https://github.com/Kyvero-Vexus/flag-empires/issues/2](https://github.com/Kyvero-Vexus/flag-empires/issues/2). Originally opened by [chrysolambda-ops](https://github.com/chrysolambda-ops) on 2026-04-03T09:34:21Z. The original account was not recreated on this Forgejo instance.
chrysolambda-ops commented 2026-04-03 13:02:40 +00:00 (Migrated from github.com)

Security triage update (2026-04-03 13:02 UTC):

  • Checked Actions policy: repo had .
  • Updated policy to .
  • Set selected-actions baseline allowlist to trusted patterns: and (with GitHub-owned actions allowed).
  • Re-verified via API: and selected-actions now reflect the baseline allowlist.

Imported from GitHub comment. Originally posted by chrysolambda-ops on 2026-04-03T13:02:40Z.

Security triage update (2026-04-03 13:02 UTC): - Checked Actions policy: repo had . - Updated policy to . - Set selected-actions baseline allowlist to trusted patterns: and (with GitHub-owned actions allowed). - Re-verified via API: and selected-actions now reflect the baseline allowlist. --- Imported from [GitHub comment](https://github.com/Kyvero-Vexus/flag-empires/issues/2#issuecomment-4183390297). Originally posted by [chrysolambda-ops](https://github.com/chrysolambda-ops) on 2026-04-03T13:02:40Z.
chrysolambda-ops commented 2026-04-03 13:02:48 +00:00 (Migrated from github.com)

Triaged and remediated ✅

  • Before: allowed_actions = all
  • After: allowed_actions = selected

Selected-actions configuration:

  • github_owned_allowed = true
  • verified_allowed = false
  • patterns_allowed = ["actions/*", "github/*"]

Verification commands:

  • gh api repos/Kyvero-Vexus/flag-empires/actions/permissions
  • gh api repos/Kyvero-Vexus/flag-empires/actions/permissions/selected-actions

Imported from GitHub comment. Originally posted by chrysolambda-ops on 2026-04-03T13:02:48Z.

Triaged and remediated ✅ - Before: `allowed_actions = all` - After: `allowed_actions = selected` Selected-actions configuration: - `github_owned_allowed = true` - `verified_allowed = false` - `patterns_allowed = ["actions/*", "github/*"]` Verification commands: - `gh api repos/Kyvero-Vexus/flag-empires/actions/permissions` - `gh api repos/Kyvero-Vexus/flag-empires/actions/permissions/selected-actions` --- Imported from [GitHub comment](https://github.com/Kyvero-Vexus/flag-empires/issues/2#issuecomment-4183390681). Originally posted by [chrysolambda-ops](https://github.com/chrysolambda-ops) on 2026-04-03T13:02:48Z.
chrysolambda-ops commented 2026-04-03 13:02:53 +00:00 (Migrated from github.com)

Security triage update (2026-04-03 13:02 UTC):

  • Confirmed prior state was allowed_actions=all.
  • Updated repository Actions policy to allowed_actions=selected.
  • Configured selected-actions baseline allowlist patterns: actions/* and github/* (github_owned_allowed=true, verified_allowed=false).
  • Re-verified via API: allowed_actions=selected and selected-actions matches baseline allowlist.

Imported from GitHub comment. Originally posted by chrysolambda-ops on 2026-04-03T13:02:53Z.

Security triage update (2026-04-03 13:02 UTC): - Confirmed prior state was allowed_actions=all. - Updated repository Actions policy to allowed_actions=selected. - Configured selected-actions baseline allowlist patterns: actions/* and github/* (github_owned_allowed=true, verified_allowed=false). - Re-verified via API: allowed_actions=selected and selected-actions matches baseline allowlist. --- Imported from [GitHub comment](https://github.com/Kyvero-Vexus/flag-empires/issues/2#issuecomment-4183390959). Originally posted by [chrysolambda-ops](https://github.com/chrysolambda-ops) on 2026-04-03T13:02:53Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Kyvero-Vexus/flag-empires#2
No description provided.