पाठ 25 / 25
A GitHub Actions Review Checklist
Before merging workflow changes.
Questions to ask
Does actionlint pass? Are triggers and path filters right, without breaking required checks? Are permissions minimal at workflow and job level? Are untrusted inputs passed through env? Are third-party actions pinned to SHAs and updated by a bot? Are secrets scoped to environments, and is OIDC used for cloud access? Are caches keyed on lockfiles? Do concurrency groups cancel stale CI runs but never deployments? Is timeout-minutes set? Is logic in versioned scripts or reusable workflows rather than copied across repositories?
The checklist
Use it in reviews of workflow changes.
[ ] actionlint clean (with shellcheck if possible)
[ ] triggers + branch/path filters correct; required checks still satisfiable
[ ] permissions: minimal per workflow/job; org default read-only
[ ] untrusted inputs only via env and quoted ("$VAR")
[ ] third-party actions pinned to commit SHAs; Dependabot updates them
[ ] no pull_request_target + checkout of PR code
[ ] secrets in environments; OIDC for cloud credentials
[ ] caches keyed on lockfile hashes
[ ] concurrency: cancel stale CI, queue deployments
[ ] timeout-minutes on every job; reusable workflows for shared pipelinesUse CODEOWNERS for workflows
Require review from a platform or security owner for changes under .github/workflows/.
त्वरित जाँच: Which item belongs on a GitHub Actions review checklist?
- Write-all token permissions by default
- Self-hosted runners for public repositories
- Third-party actions pinned to full commit SHAs
- Issue titles inserted directly into run scripts
Answer
Third-party actions pinned to full commit SHAs — Least privilege and immutable dependencies.