Search Results

Documents authored by Boschanski, Lukas


Artifact
Software
CI/CD Security Best Practices and GitHub Actions Documentation

Authors: Lukas Boschanski and Marco Vieira


Abstract

Cite as

Lukas Boschanski, Marco Vieira. CI/CD Security Best Practices and GitHub Actions Documentation (Software, Source Code). Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2026)


Copy BibTex To Clipboard

@misc{dagstuhl-artifact-27689,
   title = {{CI/CD Security Best Practices and GitHub Actions Documentation}}, 
   author = {Boschanski, Lukas and Vieira, Marco},
   note = {Software (visited on 2026-10-05)},
   url = {https://github.com/bluuuk/gh-cicd-sbp-docs},
   doi = {10.4230/artifacts.27689},
}
Document
Technical Track Paper
Evaluating CI/CD Security Best Practices in the GitHub Actions Documentation

Authors: Lukas Boschanski and Marco Vieira

Published in: LIPIcs, Volume 394, 20th International Symposium on Empirical Software Engineering and Measurement (ESEM 2026)


Abstract
Background. GitHub Actions, the most widely used Continuous Integration and Continuous Deployment (CI/CD) platform, is frequently involved in large-scale software supply chain attacks. While prior work has focused on detecting vulnerable CI/CD pipelines, research has rarely considered preventive perspectives such as analyzing Security Best Practices (SBPs) in CI/CD documentation. Aims. We investigate the completeness of the official GitHub Actions documentation from a security perspective and identify potential improvements to documenting secure CI/CD practices. Method. We employ an Large Language Model (LLM)-based documentation mining pipeline to extract security advice items verbatim. We derive actionable CI/CD SBPs from the OWASP Top 10 CI/CD Security Risks framework and conduct a qualitative analysis by mapping the extracted advice items against these best practices to assess which best practices are explicitly covered. Results. Across 639 documentation pages, we identify 459 security-related advice items, of which 288 are actionable, but only 50% of them map to actionable SBPs. These items primarily address insecure configurations and insufficient credential hygiene. Furthermore, only half of all security advice visual alerts have an adequate warning type. Conclusions. The GitHub Actions documentation lacks a consistent methodology for incorporating SBPs. Moreover, coverage of established CI/CD security best practices is uneven across OWASP risk categories, with several categories receiving little to no actionable guidance.

Cite as

Lukas Boschanski and Marco Vieira. Evaluating CI/CD Security Best Practices in the GitHub Actions Documentation. In 20th International Symposium on Empirical Software Engineering and Measurement (ESEM 2026). Leibniz International Proceedings in Informatics (LIPIcs), Volume 394, pp. 15:1-15:20, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2026)


Copy BibTex To Clipboard

@InProceedings{boschanski_et_al:LIPIcs.ESEM.2026.15,
  author =	{Boschanski, Lukas and Vieira, Marco},
  title =	{{Evaluating CI/CD Security Best Practices in the GitHub Actions Documentation}},
  booktitle =	{20th International Symposium on Empirical Software Engineering and Measurement (ESEM 2026)},
  pages =	{15:1--15:20},
  series =	{Leibniz International Proceedings in Informatics (LIPIcs)},
  ISBN =	{978-3-95977-450-5},
  ISSN =	{1868-8969},
  year =	{2026},
  volume =	{394},
  editor =	{Feldt, Robert and Paasivaara, Maria and Mendez, Daniel and Wagner, Stefan and Bar\'{o}n, Marvin Mu\~{n}oz},
  publisher =	{Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
  address =	{Dagstuhl, Germany},
  URL =		{https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ESEM.2026.15},
  URN =		{urn:nbn:de:0030-drops-279830},
  doi =		{10.4230/LIPIcs.ESEM.2026.15},
  annote =	{Keywords: CI/CD security, Software documentation, Security best practices}
}

Any Issues?
X

Feedback on the Current Page

CAPTCHA

Thanks for your feedback!

Feedback submitted to Dagstuhl Publishing

Could not send message

Please try again later or send an E-mail