Action Required: A Mixed-Methods Study of Security Practices in GitHub Actions
Yusuke Kubo, Fumihiro Kanei, Mitsuaki Akiyama, Takuro Wakai, Tatsuya Mori
摘要
GitHub Actions has become a dominant Continuous Integration/Continuous Delivery (CI/CD) platform, yet recent supply chain attacks like SolarWinds and tj-actions/changed-files highlight critical security vulnerabilities in such systems. While GitHub provides official security practices to mitigate these risks, the extent of their real-world implementation remains unknown. We present a mixed-methods study analyzing 338,812 public repositories and surveying over 100 developers to understand security practice implementation in GitHub Actions. Our findings reveal alarmingly low implementation rates across five key security practices, ranging from 0.6% to 52.9%. We identify three primary barriers: lack of awareness (up to 71.6% of non-adopters were unaware of practices), misconceptions about applicability, and concerns about operational costs. Repository characteristics such as organization ownership and recent development activity significantly correlate with better security practice implementation. Based on these empirical insights, we derive actionable recommendations that align intervention strategies with appropriate levels of automation, improve notification design to support awareness, strengthen platform- and IDE-level assistance, and clarify documentation on risks and applicability.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper13
- A Large Scale Study of User Behavior, Expectations and Engagement with Android PermissionsWeicheng Cao, Chunqiu Xia, Sai Teja Peddinti, David Lie 等USENIX Security 2021 · 被引用 42 次
- Leaving My Fingerprints: Motivations and Challenges of Contributing to OSS for Social GoodYu Huang, Denae Ford, Thomas ZimmermannICSE 2021 · 被引用 36 次
- Building and Validating a Scale for Secure Software Development Self-EfficacyDaniel Votipka, Desiree Abrokwa, Michelle L. MazurekCHI 2020 · 被引用 35 次
- Security Notifications in Static Analysis Tools: Developers' Attitudes, Comprehension, and Ability to Act on ThemMohammad Tahaei, Kami Vaniea, Konstantin Beznosov, Maria K. WoltersCHI 2021 · 被引用 35 次
- Understanding skills for OSS communities on GitHubJenny T. Liang, Thomas Zimmermann, Denae FordFSE 2022 · 被引用 31 次
相关 Paper
- Characterizing the Security of Github CI WorkflowsIgibek Koishybayev, Aleksandr Nahapetyan, Raima Zachariah, Siddharth Muralee 等USENIX Security 2022
- How do Developers Talk about GitHub Actions? Evidence from Online Software Development CommunityYang Zhang, Yiwen Wu, Tingting Chen, Tao Wang 等ICSE 2024 · 被引用 12 次
- Toward Understanding the Security of Plugins in Continuous Integration ServicesXiaofan Li, Yacong Gu, Chu Qiao, Zhenkai Zhang 等CCS 2024
- ARGUS: A Framework for Staged Static Taint Analysis of GitHub Workflows and ActionsSiddharth Muralee, Igibek Koishybayev, Aleksandr Nahapetyan, Greg Tystahl 等USENIX Security 2023
- The Effectiveness of Security Interventions on GitHubFelix Fischer, Jonas Höbenreich, Jens GrossklagsCCS 2023 · 被引用 4 次
