Revisiting Security Practices for Github Actions Workflows
Jiangnan Huang, Bin Lin · 2025
GitHub Actions, a built-in CI/CD service of GitHub released in 2019, has become one of the most widely adopted tools among developers for automating software development workflows. This popularity, however, brings security challenges, as vulnerable workflows can expose repositories and software supply chains to significant risks. Existing studies have highlighted several types of potential security issues. Over the past few years, GitHub has been constantly promoting better security practices, and developers have gained experience in using GitHub Actions. Investigating how developers' practices for handling GitHub Actions security have changed over time could offer valuable insights for further strengthening the security of these workflows. In this study, we analyzed non-optimal security practices in 18,938 workflows from 5,246 active GitHub repositories. By comparing the prevalence of issues spotted in two different years (2022 and 2024), we find that the instances of No Permissions Specified have significantly reduced as more developers now explicitly define permissions in their workflows. However, other issues, such as Confidential Data Disclosure, remain prevalent, underscoring the need for continued vigilance and further research in this domain.