GitHub Actions CI/CD Security Review Checklist Mapped to OWASP and CISA
Use this pull-request review checklist to evaluate GitHub Actions workflows for excessive permissions, unsafe third-party actions, artifact promotion gaps, secret exposure, runner isolation, and missing audit evidence. Each control is mapped to the OWASP Top 10 CI/CD Security Risks and CISA/NSA CI/CD guidance.