A Practical OWASP CI/CD Security Review Worksheet for GitHub Actions Pull Requests
Turn OWASP CI/CD risks 8, 9, and 10 into a repeatable GitHub Actions pull-request review. Use a worked workflow example to find ungoverned actions, weak artifact checks, and missing deployment evidence before code reaches production.
8 min read