DEV Community

Discussion on: Maturity levels of using GitHub Actions Securely

Collapse
 
rob_bos profile image
Rob Bos

One way that may work is to explicitly add tags to the fork with the versions that are approved. Eg @v2-approved, and then limit the allow list to each forked action repo with those specific tags (@v2-approved or @approved*)