Skip to content

Composite action security #27091

Discussion options

You must be logged in to vote
38ri581oq480:

Is it possible to add post-run steps to composite action?

I don’t see anything about that in the Metadata syntax documentation. For Docker and Javascript actions, yes, but I see no such thing for composite actions.

38ri581oq480:

Does my action leaves ssh-key in ssh-agent after run, and is it possible that my private ssh-key can be compromised by running this action on GitHub hosted runners?

The key will remain in the agent and the agent isn’t stopped, so yes, it stays available on the machine. On a GitHub hosted runner the impact should be limited because the runner VM is destroyed at the end of the job, on a self-hosted runner the stray ssh-agent might be more trou…

Replies: 9 comments

Comment options

You must be logged in to vote
0 replies
Answer selected
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
2 participants