Skip to content

Conversation

karouf
Copy link
Member

@karouf karouf commented Sep 4, 2025

Transition to Secure GitHub Actions Workflows (STEP-18 Compliance)

As part of our security enhancements, we have done the legwork to migrate approximately 100 of our 420 repositories left to no longer store secrets on GitHub servers, complying with STEP-18. We need your help to finalize this transition.
This change is required by Platform Security for all repositories that use GitHub Actions workflows.

Why This Change?

  • To eliminate the storage of sensitive data on GitHub servers, securing our operations.
  • To allow teams to manage their own secrets using Hashicorp Vault and yak

What to Do?

  • Review this PR to confirm that your workflows behave as expected with the new secrets handling method.
  • Test the workflows manually if possible, especially on this PR branch.
  • Ensure to merge this PR by 15th September. Past this date, any remaining PRs will be force merged by the Platform Security team.

Need Help?

Next Steps

  • Post-merger, be vigilant for any potential failures and address them promptly to maintain smooth operations.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant