actsense Security checks
Every issue actsense looks for, what it means, and how to fix it. 79 checks across 8 categories, run against your workflows and every dependency they pull in.
unpinned_version
Unpinned Version
Workflows that use actions with references that don't match standard pinning formats (version tags, commit SHAs, or branches) create security risks: unpinned or…
Medium
no_hash_pinning
No Hash Pinning
Workflows that pin actions to version tags (e.g., @v1, @v2.0.0) instead of commit SHAs are vulnerable to supply-chain attacks: tags are mutable—maintainers can move…
Low
short_hash_pinning
Short Hash Pinning
Workflows that pin actions to short commit SHAs (less than 40 characters) instead of full 40-character SHAs create ambiguity risks: short SHAs can collide with other…
Medium
older_action_version
Older Action Version
Workflows using older major versions of actions (v1, v2) when newer versions (v3+, v4+) are available expose themselves to known security vulnerabilities that have…
Low
inconsistent_action_version
Inconsistent Action Version
Using the same action with different versions across workflows means some jobs miss security patches while others get them.
High
unpinnable_docker_image
Unpinnable Docker Image
Docker actions that use mutable tags (e.g., latest, v1, v1.2) instead of immutable digests create supply-chain risks: tags can be moved to point to different images,…
High
unpinnable_composite_subaction
Unpinnable Composite Subaction
Composite actions that use sub-actions with tags or branches instead of commit SHAs create transitive dependency risks: tags and branches can be moved or updated,…
High
unpinned_javascript_resources
Unpinned Javascript Resources
JavaScript actions that download external resources (scripts, binaries, archives) without checksum verification create supply-chain security risks: downloaded…overly_permissive
Overly Permissive
Workflows with write permissions to GitHub Actions can create, modify, or delete actions in the repository.
High
github_token_write_all
GitHub Token Write-All
Setting permissions: write-all grants the workflow token write access to every API scope (contents, issues, packages, etc.).
High – Medium
github_token_write_permissions
GitHub Token Write Permissions
Even when you avoid write-all, a workflow can still enumerate multiple write scopes (contents, issues, pull-requests, packages) that the jobs never use.
Medium
excessive_write_permissions
Excessive Write Permissions
GitHub Actions defaults the GITHUBTOKEN to contents: read / packages: write, but many workflows override permissions: write-all even when they only run tests or lint.
Low
missing_permissions
Missing Permissions Block
When a workflow does not declare a permissions block — and not every job sets its own — the GITHUBTOKEN falls back to the repository or organization default permissions.
High
branch_protection_bypass
Branch Protection Bypass
Workflows that auto-approve or auto-merge pull requests undermine GitHub branch protection: they short-circuit required reviewers, status checks, and manual merges.
High
token_permission_escalation
Token Permission Escalation
Workflows that manipulate GITHUBTOKEN directly (base64 encoding, echoing to logs, passing in command-line arguments) create security risks: tokens can be extracted…potential_hardcoded_secret
Potential Hardcoded Secret
Workflows containing hardcoded secrets (passwords, API keys, tokens, database credentials) expose those credentials to anyone with read access to the repository.
Critical
potential_hardcoded_cloud_credentials
Potential Hardcoded Cloud Credentials
Workflows that contain hardcoded cloud credentials (AWS keys, Azure secrets, GCP service account keys) in run commands expose those credentials to anyone with read…
High
long_term_cloud_credentials
Long Term Cloud Credentials
Storing static cloud provider credentials (AWS, Azure, or GCP) in GitHub secrets means the keys never expire.
High
secret_in_environment
Secret In Environment
Workflows that expose secrets directly in environment variables create security risks: environment variables may be logged by actions or tools, visible in workflow…
Medium
secrets_access_untrusted
Secrets Access Untrusted
Workflows that pass secrets to untrusted third-party actions create extreme supply-chain risks: untrusted actions may be malicious, compromised, or contain…
Critical
secrets_in_matrix
Secrets In Matrix
Workflows that include secrets in matrix strategy definitions expose those secrets to ALL matrix job combinations: each matrix job can access and potentially log the…
Medium
environment_with_secrets
Environment With Secrets
GitHub environments act as secret vaults plus deployment gates, but if you attach an environment to a job without configuring protection rules, any workflow with…
High
excessive_secret_exposure
Excessive Secret Exposure
The secrets context can be serialized in bulk with the toJson(secrets) expression.
Medium
secrets_inherit
Reusable Workflow Secrets Inheritance
When one workflow calls a reusable workflow, it can forward credentials with secrets: inherit.
Medium
secrets_outside_env
Secrets Used Outside Environment Variables
Interpolating a secret directly into a run: command — deploy --token ${{ secrets.TOKEN }} — places the plaintext value on the command line, where it can leak through…
High
hardcoded_container_credentials
Hardcoded Container Credentials
Jobs can run inside a container or spin up service containers that pull from a private registry, authenticating with container.credentials / services..credentials.
Critical – High
trufflehog_secret_detected
Secret Detected by TruffleHog
TruffleHog matched a known credential format (a cloud key, API token, private key, etc.) in the workflow file.
Low
optional_secret_input
Optional Secret Input
An action declares an input whose description says it carries a secret, password, or token, but marks it required: false with no default.dangerous_event
Dangerous Event
GitHub Actions runs workflow code from trusted workflow definitions on the default branch for most events.
Critical – High
insecure_pull_request_target
Insecure Pull Request Target
pullrequesttarget runs with the base repository’s token (Usually write).
High – Medium
unsafe_checkout
Unsafe Checkout
Workflows that use actions/checkout with persist-credentials: true create security risks: credentials are stored in the runner's Git configuration, subsequent steps…
Medium
unsafe_checkout_ref
Unsafe Checkout Ref
Workflows that use actions/checkout with refs containing variables that may not be properly validated create security risks: if the ref comes from user input…
Low
checkout_full_history
Checkout Full History
Setting actions/checkout to fetch-depth: 0 clones the entire repository history into the runner.
Critical
script_injection
Script Injection
Workflows that use user-controlled input in dangerous PowerShell operations (Invoke-Expression, Invoke-Command, call operators) are vulnerable to script injection:…
Critical – High
shell_injection
Shell Injection
Workflows that pipe user-controlled input directly to shell interpreters (bash, sh, zsh) without validation create code injection vulnerabilities: attackers can…
Critical – Low
risky_context_usage
Risky Context Usage
Workflows that use user-controllable GitHub context variables (such as github.event.issue.body, github.event.pullrequest.title, github.refname, etc.) create injection…
Critical
github_env_injection
GitHub Environment File Injection
GitHub Actions exposes the special files $GITHUBENV and $GITHUBPATH so that a step can set environment variables and prepend directories to PATH for subsequent steps…
High
github_output_injection
GitHub Output File Injection
A step can publish outputs to later steps and jobs by appending key=value lines to the special $GITHUBOUTPUT file.
High
insecure_commands
Insecure Workflow Commands
GitHub Actions once let steps set environment variables and modify PATH by printing ::set-env and ::add-path stdout commands.
Medium
spoofable_actor_condition
Spoofable Actor Condition
Workflows sometimes gate privileged behaviour on the actor context — for example if: github.actor == 'dependabot[bot]' — to "only run for a trusted user or bot." The…
High – Medium
code_injection_via_input
Code Injection via Input
Workflows that accept workflowdispatch inputs and interpolate them directly into shell commands give untrusted users a remote code execution primitive: an attacker…
Medium
unvalidated_workflow_input
Unvalidated Workflow Input
Workflows with workflowdispatch inputs that are optional or used in shell commands without validation create security risks: optional inputs may be used without…
Medium
unsafe_shell
Unsafe Shell
A step that runs Bash without exit-on-error keeps going after a command fails.untrusted_action_source
Untrusted Action Source
Workflows that use actions from untrusted third-party publishers create supply-chain security risks: actions can contain malicious code, run with your workflow's…
High
untrusted_action_unpinned
Untrusted Action Unpinned
Untrusted third-party actions that are not pinned to a specific version create critical security risks: the action can be updated by the maintainer at any time,…
High
typosquatting_action
Typosquatting Action
Workflows using actions with suspicious naming patterns (similar to popular actions but with slight variations) may be victims of typosquatting attacks: attackers…
Medium
deprecated_action
Deprecated Action
Running outdated versions of community actions leaves workflows exposed to known vulnerabilities—GitHub often revs v1 actions multiple times to address security flaws.
Critical
missing_action_repository
Missing Action Repository
Workflows that reference actions from repositories that don't exist or are inaccessible will fail at runtime, disrupting CI/CD pipelines and potentially causing…
Medium
ref_version_mismatch
Action Ref / Version Comment Mismatch
Pinning an action to a full commit SHA is the most secure way to reference it, and the common convention is to annotate the SHA with the human-readable version it…
High
unpinned_dockerfile_dependencies
Unpinned Dockerfile Dependencies
Docker actions with Dockerfiles that install Python packages (or other dependencies) without version pinning create security and reproducibility risks: package…
High
unpinned_dockerfile_resources
Unpinned Dockerfile Resources
Docker actions with Dockerfiles that download external resources (scripts, binaries, archives) without checksum verification create security risks: downloaded…
High
unpinned_external_resources
Unpinned External Resources
Composite actions that download external resources (scripts, binaries, archives) without checksum verification create security risks: downloaded resources can be…
High
unpinned_javascript_resources
Unpinned Javascript Resources
JavaScript actions that download external resources (scripts, binaries, archives) without checksum verification create supply-chain security risks: downloaded…
High
unpinned_npm_packages
Unpinned Npm Packages
Workflows and composite actions that install NPM packages without version locking create security and reproducibility risks: package versions can change between runs,…
High
unpinned_python_packages
Unpinned Python Packages
Workflows and composite actions that install Python packages without version pinning create security and reproducibility risks: package versions can change between…
Low
unfiltered_network_traffic
Unfiltered Network Traffic
Workflows that perform network operations (curl, wget, ssh, etc.) without filtering or monitoring create security risks: network traffic can be used to exfiltrate…
Low
no_file_tampering_protection
No File Tampering Protection
Build jobs that modify files during execution without integrity checks are vulnerable to supply-chain tampering: malicious actions or compromised dependencies can…self_hosted_runner
Self Hosted Runner
Workflows using self-hosted runners pose significant security risks compared to GitHub-hosted runners: self-hosted runners have persistent access to your…
Critical
self_hosted_runner_pr_exposure
Self Hosted Runner Pr Exposure
Self-hosted runners exposed to pull requests in public repositories create extreme security risks: attackers from forks can create PRs that trigger workflows on your…
High
self_hosted_runner_issue_exposure
Self Hosted Runner Issue Exposure
Self-hosted runners that can be triggered by issue events in public repositories create significant security risks: anyone can create issues in public repositories,…
Critical
self_hosted_runner_write_all
Self Hosted Runner Write All
Self-hosted runners with write-all permissions create extreme security risks: write-all grants excessive access to repository resources, and if the runner is…
High
self_hosted_runner_secrets_in_run
Self Hosted Runner Secrets In Run
Workflows that use secrets directly in run commands on self-hosted runners expose those secrets to process lists, shell history, and logs: secrets may be visible in…
High
self_hosted_runner_network_risk
Self Hosted Runner Network Risk
Self-hosted runners that download and execute code from the internet without verification create significant security risks: downloaded scripts may be malicious,…
High
runner_label_confusion
Runner Label Confusion
Workflows using runner labels that are confusing or similar to GitHub-hosted runner labels (e.g., ubuntu-latest, windows-latest, self-hosted-ubuntu) create security…
Critical
public_repo_self_hosted_secrets
Public Repo Self Hosted Secrets
Self-hosted runners in public repositories that have access to secrets create extreme security risks: public repos are accessible to anyone, so attackers can analyze…
High
public_repo_self_hosted_environment
Public Repo Self Hosted Environment
Self-hosted runners in public repositories that access protected environments create significant security risks: public repos are accessible to anyone, so attackers…continue_on_error_critical_job
Continue-on-Error Critical Job
Marking a critical deployment or verification step with continue-on-error: true hides failures—CI passes even when that step fails, so broken releases or incomplete…
Low
long_artifact_retention
Long Artifact Retention
GitHub Actions artifacts default to a 90-day retention period, but workflows can override it up to 400 days.
Low
large_matrix
Large Matrix
Matrix jobs that explode into dozens or hundreds of combinations slow feedback loops, burn runner minutes, and make it easy to miss failures (logs become overwhelming).
Low
insufficient_audit_logging
Insufficient Audit Logging
Deploy or publishing jobs that fetch secrets, push artifacts, or touch production often run without structured logging.
High
environment_bypass_risk
Environment Bypass Risk
Workflows triggered by pullrequesttarget, workflowrun, or other elevated events can call protected environments without the usual approval gates.
High
cross_repository_access
Cross Repository Access
When a workflow checks out or clones a repository other than the one that triggered it, any secrets granted to the workflow can cross trust boundaries.
High
cross_repository_access_command
Cross Repository Access Command
Workflows that run shell commands like git clone https://github.com/foo/bar or curl https://raw.githubusercontent.com/... pull code straight from external repositories.malicious_curl_pipe_bash
Malicious Curl Pipe Bash
curl ... | bash downloads and executes remote code in one step with zero verification.
Critical
malicious_base64_decode
Malicious Base64 Decode
Attackers often smuggle malicious scripts in base64-encoded strings, then decode and execute them inside workflows (base64 -d | bash).
Critical – Medium
obfuscation_detection
Obfuscation Detection
Workflows containing obfuscated code patterns (base64 encoding, hex escapes, nested command substitution, variable expansion tricks) are suspicious because…
Critical – Low
artifact_exposure_risk
Artifact Exposure Risk
Uploading workflow artifacts with overly broad path patterns, missing retention policies, or unsafe configurations can create risks of exposing sensitive files…
Medium
artifact_poisoning
Artifact Poisoning
Workflows triggered by workflowrun or pullrequesttarget run in a privileged context (secrets, write-scoped token) but are often kicked off by a build that ran…
High
cache_poisoning
Cache Poisoning
GitHub Actions caches (via actions/cache or the built-in caching of setup- actions) are shared across workflow runs to speed up builds.No checks match these filters.