Hardening GitHub Actions with Least Privilege
A practical guide to reduce CI/CD risk by granting the minimum GITHUB_TOKEN permissions per job, favoring job-level scoping, and separating read-only CI from privileged publish/deploy steps.

A practical guide to reduce CI/CD risk by granting the minimum GITHUB_TOKEN permissions per job, favoring job-level scoping, and separating read-only CI from privileged publish/deploy steps.

Start workflows with no permissions and explicitly add only the GITHUB_TOKEN scopes each job needs.
Prefer job-level permissions over workflow-wide write access to limit what a compromised action or script can do.
# Why least privilege matters for GitHub Actions GitHub Actions supplies a temporary GITHUB_TOKEN to workflow jobs. That token can modify repository contents, create releases, publish packages, update pull requests, create deployments, and request an id-token for federated auth. If a job receives more privileges than it needs, a compromised action, dependency, or injected command can use those privileges to broaden an attacker's access. Minimizing token scope reduces that blast radius.
# Core hardening principles
# How GITHUB_TOKEN permissions behave GitHub creates a temporary GITHUB_TOKEN for each job and ties its capabilities to the permissions declared for the job or workflow. Common permission scopes include contents (read/write), pull-requests (write), issues (write), packages (write), deployments (write), security-events (write), attestations (write), and id-token (write). The token expires when the job completes.
# Practical workflow pattern
# Example roles for jobs
# Why explicit job-level permissions help reviews and portability Relying on implicit permission defaults can hide the effective scope of GITHUB_TOKEN, because defaults may vary by repo, org, or enterprise settings. Explicit permissions make the intended security boundary visible in the workflow file, which helps reviewers spot overly broad access and prevents accidental privilege expansion when copying workflows between repositories.
# Small checklist to harden a workflow
# Bottom line Treat GITHUB_TOKEN as a scarce capability. Design CI/CD pipelines so the majority of jobs run with read-only access, and grant write or other sensitive scopes only where necessary and isolated. This reduces the potential impact of compromised actions, dependencies, or injected commands and makes workflows easier to review and re-use safely.

GitHub’s new workflow execution protections let teams control who and what can trigger Actions workflows, reducing CI/CD attack paths and tightening pipeline security.

The principle of least privilege is straightforward to articulate but challenging to maintain at scale. When teams first deploy applications to AWS, they often grant broader permissions than strictly necessary; it’s faster to get things working, and the plan is always to tighten permissions later. But later rarely come
Nine seconds. That's how long it took an AI coding agent to delete a production database and its backups at PocketOS, a car-rental software vendor, in April 2026. By founder Jer Crane's account, an AI coding agent hit a credential mismatch during a routine staging task, searched the codebase, and found an API token in

Wire Amazon Bedrock AgentCore Evaluations into a GitHub Actions pipeline: deploy an AI agent and an OAuth-protected MCP server to AgentCore runtime, invoke the agent with test prompts, score the responses, and automatically block pull requests when agent behavior regresses.

When people think about software development, they often picture developers sitting in front of computers and writing code. Coding is… Continue reading on Medium »

Enterprise autonomous software development platform Blitzy today announced the launch of the Blitzy Sandbox, a trial environment that allows organizations to evaluate the platform on their own software estates at no cost. The offering enables eligible enterprises to ingest up to 1 million lines of code and generate up
Loading more related stories...
Open the app view to save this story, compare related coverage, and continue from the same source.