GitHub Actions SHA Pinning: A Practical Security Review Checklist By - CodeRiskTools EditorialPosted on August 3, 2026Posted in CI SecurityReview GitHub Actions supply-chain risk with full commit-SHA pins, least-privilege permissions, and a repeatable pull-request checklist.
GitHub Copilot App Access Policy: An Enterprise Security Review Checklist By - CodeRiskTools EditorialPosted on August 2, 2026Posted in Secure CodingReview GitHub Copilot app access policies, managed settings, client separation, repository scope, and rollback evidence before enterprise rollout.
Copilot Code Review Agent Skills and MCP: A Security Review Checklist By - CodeRiskTools EditorialPosted on August 1, 2026Posted in AI Code Review, CI and Release GatesA practical security review checklist for Copilot code review agent skills and MCP tools, with bounded permissions and human approval.
GitHub Actions Workflow Approval Holds: A Security Review Checklist By - CodeRiskTools EditorialPosted on August 1, 2026August 1, 2026Posted in CI Security, Secure CodingGitHub now holds certain potentially malicious GitHub Actions runs for approval in public repositories. Use this bounded review checklist before approving a held workflow.