Action Required: A Mixed-Methods Study of Security Practices in GitHub Actions
Yusuke Kubo, Fumihiro Kanei, Mitsuaki Akiyama, Takuro Wakai, Tatsuya Mori
Abstract
GitHub Actions has become a dominant Continuous Integration/Continuous Delivery (CI/CD) platform, yet recent supply chain attacks like SolarWinds and tj-actions/changed-files highlight critical security vulnerabilities in such systems. While GitHub provides official security practices to mitigate these risks, the extent of their real-world implementation remains unknown. We present a mixed-methods study analyzing 338,812 public repositories and surveying over 100 developers to understand security practice implementation in GitHub Actions. Our findings reveal alarmingly low implementation rates across five key security practices, ranging from 0.6% to 52.9%. We identify three primary barriers: lack of awareness (up to 71.6% of non-adopters were unaware of practices), misconceptions about applicability, and concerns about operational costs. Repository characteristics such as organization ownership and recent development activity significantly correlate with better security practice implementation. Based on these empirical insights, we derive actionable recommendations that align intervention strategies with appropriate levels of automation, improve notification design to support awareness, strengthen platform- and IDE-level assistance, and clarify documentation on risks and applicability.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 101cf7f3-324b-402c-9eb0-03dda14fb067Builds on13
- A Large Scale Study of User Behavior, Expectations and Engagement with Android PermissionsWeicheng Cao, Chunqiu Xia, Sai Teja Peddinti, David Lie et al.USENIX Security 2021 · 42 citations
- Leaving My Fingerprints: Motivations and Challenges of Contributing to OSS for Social GoodYu Huang, Denae Ford, Thomas ZimmermannICSE 2021 · 36 citations
- Building and Validating a Scale for Secure Software Development Self-EfficacyDaniel Votipka, Desiree Abrokwa, Michelle L. MazurekCHI 2020 · 35 citations
- Security Notifications in Static Analysis Tools: Developers' Attitudes, Comprehension, and Ability to Act on ThemMohammad Tahaei, Kami Vaniea, Konstantin Beznosov, Maria K. WoltersCHI 2021 · 35 citations
- Understanding skills for OSS communities on GitHubJenny T. Liang, Thomas Zimmermann, Denae FordFSE 2022 · 31 citations
Related papers
- Characterizing the Security of Github CI WorkflowsIgibek Koishybayev, Aleksandr Nahapetyan, Raima Zachariah, Siddharth Muralee et al.USENIX Security 2022
- How do Developers Talk about GitHub Actions? Evidence from Online Software Development CommunityYang Zhang, Yiwen Wu, Tingting Chen, Tao Wang et al.ICSE 2024 · 12 citations
- Toward Understanding the Security of Plugins in Continuous Integration ServicesXiaofan Li, Yacong Gu, Chu Qiao, Zhenkai Zhang et al.CCS 2024
- ARGUS: A Framework for Staged Static Taint Analysis of GitHub Workflows and ActionsSiddharth Muralee, Igibek Koishybayev, Aleksandr Nahapetyan, Greg Tystahl et al.USENIX Security 2023
- The Effectiveness of Security Interventions on GitHubFelix Fischer, Jonas Höbenreich, Jens GrossklagsCCS 2023 · 4 citations
