Apply Security Best Practices
Secure Workflow
Restrict permissions for GITHUB_TOKEN
Add security agent for GitHub-hosted runner
Pin actions to a full length commit SHA