Synthetic Industry

Troubleshooting guide · updated 2026-10-10

Before adding a third-party GitHub Action, check what code and credentials it can use

Review the action's source, immutable reference and job permissions rather than treating a familiar tag or marketplace listing as a security guarantee.

Treat an action as executable dependency code

A team is about to add or update a build, deployment or reporting action. Identify the exact source repository and revision, who maintains it and which job will execute it. An action's popularity does not establish that the implementation is safe for the credentials in your workflow. Read its entry point and dependencies for network transmission, unexpected logging and commands outside the stated task.

  • Include downloaded tools and reusable workflows in the review boundary.
  • Do not execute unfamiliar action code merely to inspect it.

Pinning stabilises identity, not safety

GitHub identifies a full-length commit SHA as the immutable reference. A version tag can move, even under a trusted publisher. Verify that the SHA belongs to the intended upstream repository, not a fork. Pinning prevents an unnoticed tag change from selecting new code; it does not prove the pinned code is benign or keep it updated automatically.

  • Record the reviewed upstream revision and reason for the update.
  • Do not paste an arbitrary SHA copied from an unrelated issue into a privileged job.

Limit the credentials exposed to the job

Inspect job and workflow permissions together and supply only the secrets actually required. A compromised action may use repository token permissions or expose credentials available to it. Separate untrusted contribution tests from privileged release work. Maintain an explicit update route: a fixed reference still needs review when its dependencies or functionality change.

  • Review the actual permission delta before approving an action update.
  • Never print environment variables or tokens as review evidence.

What a bounded review can establish

A handover can identify the reviewed implementation, fixed reference, approved permissions and passing intended workflow behaviour. It cannot certify all transitive code or guarantee freedom from compromise. This guide is not a newly offered security audit. Ask about a named workflow change or scoped recurring CI responsibility; access, review depth and price are agreed before work.

Sources and limits

  • GitHub: security hardening for GitHub Actions Checked 2026-10-10.
    • A full-length commit SHA is the immutable way to pin an action; tags can move or be removed.
    • An action can expose secrets and use job token permissions; review implementation and minimise permissions.
    • Externally maintained reusable workflows require the same trust precautions.