GitHub Actions

Continuous integration and release automation running on GitHub.

adds it to an existing project · no account needed
Currentas published in v1.5.1

The rule

This is the whole text, exactly as your agent receives it. Nothing is held back for the paid tier.

Secrets

  • Repository or environment secrets only. A secret committed to a workflow file is leaked to everyone with read access, and rewriting history does not undo it.
  • Never echo a secret, and never pass one into an untrusted action.

Permissions

yaml
permissions:
  contents: read

Set explicitly at the top of every workflow. The default is broader than any test job needs, and a compromised action inherits whatever the job holds.

Actions

  • Pin third-party actions to a commit SHA, not a tag. Tags are mutable, and the action runs with access to your secrets.
  • First-party actions/* at a major version tag is acceptable.

Fork pull requests

  • pull_request deliberately withholds secrets from forks.
  • Never switch to pull_request_target to work around that. It runs with full secret access against untrusted code — a known exfiltration path.

Efficiency

  • concurrency with cancel-in-progress on pull request workflows.
  • Cache the dependency manager via setup-node.

Deployment

  • Separate workflow, triggered by tag or manual dispatch.
  • Target a GitHub environment with required reviewers. Do not deploy automatically from every green build.

6 formats, one per tool

Each tab is the file that tool actually reads, at the path it actually looks in. Knowing where each one looks is most of the work of supporting it.

.cursor/rules/github-actions.mdchand-written
---
description: GitHub Actions conventions
globs: [".github/workflows/**"]
alwaysApply: false
---

# GitHub Actions

## Secrets

- Repository or environment secrets only. A secret committed to a workflow file
  is leaked to everyone with read access, and rewriting history does not undo it.
- Never echo a secret, and never pass one into an untrusted action.

## Permissions

```yaml
permissions:
  contents: read
```

Set explicitly at the top of every workflow. The default is broader than any
test job needs, and a compromised action inherits whatever the job holds.

## Actions

- Pin third-party actions to a **commit SHA**, not a tag. Tags are mutable, and
  the action runs with access to your secrets.
- First-party `actions/*` at a major version tag is acceptable.

## Fork pull requests

- `pull_request` deliberately withholds secrets from forks.
- **Never** switch to `pull_request_target` to work around that. It runs with
  full secret access against untrusted code — a known exfiltration path.

## Efficiency

- `concurrency` with `cancel-in-progress` on pull request workflows.
- Cache the dependency manager via `setup-node`.

## Deployment

- Separate workflow, triggered by tag or manual dispatch.
- Target a GitHub environment with required reviewers. Do not deploy
  automatically from every green build.

Hand-written by the module author, frontmatter and all. It is the source the four derived formats are rendered from, so a correction lands here first.

What else this module writes

The rule is one file of several. Selecting GitHub Actions contributes all of this too — merged with every other module you pick, with conflicts resolved rather than duplicated.

Environment
CIoptionalSet by the runner. Use it to skip prompts and enable machine-readable output.

Advisory history

Every time this rule turned out to be wrong, and what we did about it.

No corrections yet

This rule has been accurate since it was published. That is a fact about the rule, not a promise about the future — which is the whole reason this section exists.

Pro tells you the day a correction lands that affects a repo you actually have.

See what Pro adds →

Rules people add alongside this one

Put this rule in a real project

The wizard picks the rest of the stack with you, writes all 6 formats, and leaves a manifest so check can tell you when any of it drifts.