Category: Secure Coding

Secure coding guidance for AI-assisted development, including input validation, dependency risk, configuration safety, testing, and release controls.

Engineer reviewing GitHub Actions self-hosted runner maintenance and deployment workflow

GitHub-Hosted Runner Groups: A Security Review Checklist for Policy-Controlled CI

GitHub is adding more policy control around GitHub-hosted runners, including runner groups that can direct jobs to runners meeting an organization’s requirements and the ability to disable standard hosted runners. That is useful for platform teams, but a policy setting is not the same thing as a verified security boundary. The practical question is: what
Loading, please wait…
BACK TO TOP