DUE TO SPAM, SIGN-UP IS DISABLED. Goto Selfserve wiki signup and request an account.
...
The Apache Infrastructure GitHub Actions Policy has the formal rules around the use of GitHub actions. The content below is intended to be more practical advice.
IMPORTANT! You should enable CodeQL "actions" scanning in your repositories as described in https://github.blog/security/application-security/how-to-secure-your-github-actions-workflows-with-codeql/ - this will scan and flag those issues described below and many more automatically for you
Threat model
We're trying to protect:
...
We mainly focus on attacks that can be triggered by external attackers, though ideally compromised committer accounts should also be considered.
Helpful tools
There are some validation tools that can help you identify risky patterns in your actions:
- Zizmor can be ran standalone or as a workflow
- CodeQL "Actions" scanning
- The ASF Infra team has a scanner for flagging obvious policy violations
- The ASF Tooling team is working on a scanner, though results are not public yet.
Workflow approval
By default, ASF repositories require approval before building PRs by non-committers.This has some limitations:
...
There are some typical tasks done wit pull_request_target - for example labeling PRs with https://github.com/actions/labeler. Those could be often replaced with GitHub Apps - for example there is a "Boring Cyborg" GitHub App: https://github.com/kaxil/boring-cyborg that has similar functionality (among others). Also Boring Cyborg could be extended if some functionalities are missing. PRs are most welcome.It's highly recommended to use https://woodruffw.github.io/zizmor/ static analysis tool in your CI / pipelines to detect and fix potential security issues in your workflows.
Builds triggered with pull_request_target
...