Skip to content

ghafiles

This contains baseline GitHub Actions that may be useful for any new project.

  • Adhere to least privilege principles for workflow permissions
  • Use of commit hashes for pinning GitHub Actions dependencies
  • Use of Dependabot to update commit hashes as necessary
  • Use of andrej-karpathy-skills as CLAUDE.md starting point
  • Use of OpenSSF's Security Scorecard (SCORECARD_TOKEN setup required)
  • Use of Step Security's Harden Runner
  • Codespell
  • Super-Linter
  • Semgrep CE
  • (optional) Sync commits to GitLab (GITLAB_TOKEN setup required)
    • Create PAT on GitLab with API, repo read and repo write permissions
    • Add PAT into GitHub repo as a secret named GITLAB_TOKEN

About

GitHub Action Templates

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

3 stars

Watchers

2 watching

Forks

Releases

Used by

Contributors

Languages