Your Pipeline Holds the Keys
Review workflow changes, third-party actions, token permissions and secret access. A related technical-security module.
Illustrative scenario
How It Looks in Real Life
A contributor’s pull request edits a workflow file to run on pull_request_target and print environment variables “for debugging”.
Understand it
How the Attack Works
CI systems run code with access to deployment secrets. Unpinned third-party actions, broad default token permissions and workflows triggered by untrusted input can expose secrets or alter releases.
Red flags
Warning Signs
- Pull requests that modify workflow files alongside unrelated changes.
- Third-party actions referenced by a moving tag instead of a commit SHA.
- Workflows granting write permissions by default.
Safer habits
What to Do Instead
- 1Require review for workflow file changes.
- 2Pin third-party actions to full commit SHAs and set minimal token permissions.
- 3Avoid exposing secrets to workflows triggered by untrusted forks.
Response playbook
Already Interacted?
For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.
If you: exposed a token, key or secret
- 1Revoke or rotate the exposed secret at the provider first; deleting the commit or message is not enough.
- 2Report it to the security team with where and when it was exposed. Never paste the secret itself into the report.
- 3Review provider logs for use of the key after the exposure time.
Knowledge Check
What Would You Do?
Which reference to a third-party action is safest?
Fictional example for learning. Not a test score or certification.
Sources
Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.
Make Safe Habits Part of Your Culture
Plain-language awareness sessions for everyday staff, developers and business teams.