CI/CD & Workflow Security

    Your Pipeline Holds the Keys

    Review workflow changes, third-party actions, token permissions and secret access. A related technical-security module.

    Developer & Technical SecurityDevelopersIT & help desk

    Illustrative scenario

    How It Looks in Real Life

    A contributor’s pull request edits a workflow file to run on pull_request_target and print environment variables “for debugging”.

    Understand it

    How the Attack Works

    CI systems run code with access to deployment secrets. Unpinned third-party actions, broad default token permissions and workflows triggered by untrusted input can expose secrets or alter releases.

    Red flags

    Warning Signs

    • Pull requests that modify workflow files alongside unrelated changes.
    • Third-party actions referenced by a moving tag instead of a commit SHA.
    • Workflows granting write permissions by default.

    Safer habits

    What to Do Instead

    • 1Require review for workflow file changes.
    • 2Pin third-party actions to full commit SHAs and set minimal token permissions.
    • 3Avoid exposing secrets to workflows triggered by untrusted forks.

    Response playbook

    Already Interacted?

    For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.

    If you: exposed a token, key or secret
    1. 1Revoke or rotate the exposed secret at the provider first; deleting the commit or message is not enough.
    2. 2Report it to the security team with where and when it was exposed. Never paste the secret itself into the report.
    3. 3Review provider logs for use of the key after the exposure time.

    Knowledge Check

    What Would You Do?

    Which reference to a third-party action is safest?

    Fictional example for learning. Not a test score or certification.

    Sources

    Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.

    All Awareness Guides

    Make Safe Habits Part of Your Culture

    Plain-language awareness sessions for everyday staff, developers and business teams.

    Email Us