Hardening GitHub Actions Against Repository-Scanning Abuse: A Worked Checklist
Reported abuse involving Packagist repositories shows how a CI workflow can become a free scanning and egress service. Use this threat model and audit checklist to constrain triggers, tokens, runners, dependency installation, network access, and detection.
8 min read