Skip to content
XEIZE
DocsIntegrations

Get started

  • Overview

Security tools

  • SAST
  • SCA

Integrations

Reference

    • Overview
      • Overview
        • Overview
          • Overview
          • GitHub Actions run block command injection
          • GitHub Actions script block injection
          • GitHub Actions not pinned to a full commit SHA
          • GitHub Actions permits insecure commands
  • Glossary

Advanced usage

  • CLI
/Vulnerability documentation/IaC/CI/CD/GitHub

GitHub

Guidance on command injection and workflow execution security in GitHub Actions.

Documentation

Article Path
GitHub Actions run block command injection cicd/github/run_block_injection
GitHub Actions script block injection cicd/github/script_block_injection
GitHub Actions not pinned to a full commit SHA cicd/github/unpinned_actions_full_length_commit_sha
GitHub Actions permits insecure commands cicd/github/unsecured_commands

Related pages4

GitHub Actions run block command injection

Pass untrusted GitHub Actions event values as data instead of inserting them directly into shell code.

GitHub Actions script block injection

Pass external values to actions/github-script as JavaScript data instead of embedding them in code.

GitHub Actions not pinned to a full commit SHA

Pin external actions to a verified full commit SHA to reduce unexpected changes to the referenced code.

GitHub Actions permits insecure commands

Remove the GitHub Actions setting that permits insecure commands and use environment files.

PreviousCI/CD
NextGitHub Actions run block command injection
XEIZE DocumentationTechnical support
On this page
Documentation