- Policies for Repository Security Posture Management (RSPM) in GitHub.
- Policies for evaluating configuration settings in workflow file.
GitHub Action policies
Learn about the out-of-the-box finding policies for GitHub Actions.
Endor Labs provides the following out-of-the-box policies that help you assess the security posture of GitHub Actions used in your software delivery process. Findings from these templates appear after you enable GitHub Actions scanning.