Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

After a suspected supply-chain attack, secure GitHub in stages: contain the activity supported by the evidence, investigate affected credentials and repositories, then apply consistent controls to code changes, dependencies, and builds. Disabling everything can disrupt legitimate work, while simply rotating a token can leave an attacker’s changes or access path in place. No setting can guarantee another attack will not happen; the aim is to limit what an attacker can reach, detect what changed, and make releases easier to verify.

1. Scope the incident before choosing containment measures

Start with the signal that triggered the response: for example, an exposed credential, an unexpected workflow run, a suspicious commit, an unfamiliar webhook, or a concern about a runner. Map the possible reach of that signal before treating one repository as the whole incident.

Build a scope map

Identify the repositories, user and service identities, tokens, workflows, runners, artifacts, and downstream releases that may be connected. Record which items are confirmed affected and which are only under investigation. That distinction helps responders choose actions proportionate to the evidence and prevents an assumption about one repository from becoming an organization-wide blind spot.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Contain the confirmed threat

Depending on what the evidence supports, containment may mean revoking affected credentials, restricting access, canceling suspicious workflow runs, disabling a suspect webhook, removing a self-hosted runner, or deleting a malicious branch. GitHub also documents disabling Actions for a repository or organization as an option. These measures differ in impact: disabling Actions can stop legitimate automation, and restricting access can interrupt development. Choose the least disruptive action that meaningfully reduces the active risk, and record what was done, when, by whom, and why. See GitHub’s incident-response guidance for the available containment choices and their disruption caveat.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

2. Investigate access and repository changes before declaring recovery

Containment stops or limits activity; it does not establish what happened. Review audit activity associated with suspected compromised tokens and identities, inspect repository history and configuration changes, and examine relevant secret-scanning alerts and exposed code. GitHub’s incident investigation areas describe these lines of inquiry.

Track credentials through their downstream use

For each credential suspected of exposure, document whether it was revoked or rotated and determine which repositories, workflows, or external systems could use it. A credential change is not a complete recovery if a workflow still exposes a replacement secret, or if unauthorized code remains in a branch or release path.

Keep the investigation tied to evidence

Compare findings against the initial scope map and update it as indicators change. The cited GitHub guidance does not prescribe one universal log-retention period or a complete forensic procedure, so set investigation depth and evidence preservation according to your organization’s incident process and obligations rather than assuming a single retention rule fits every case.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

3. Establish a consistent organization-wide baseline

Once immediate containment is underway, reduce repository-by-repository drift. GitHub security configurations collect feature-enablements that can be applied across an organization’s repositories; global settings govern organization-level features. Use these mechanisms to establish a baseline, assign an owner to exceptions, and periodically review whether each exception is still needed. GitHub explains the distinction in its guide to enabling security features at scale.

Do not assume every security feature is available to every organization or repository. Availability can depend on the plan, repository visibility, and feature. For example, GitHub’s security-feature documentation states that artifact attestations on Free, Pro, or Team are available for public repositories; private or internal repository use requires Enterprise Cloud. Check the current GitHub security feature and plan information before setting a policy around a specific control.

4. Make code and dependency changes reviewable

Protect the path into the default branch

Require pull requests and appropriate review before changes reach important branches. Require the checks that match each repository’s risk and release process; a check only provides a merge gate when the repository’s rules make it required. Review workflow and repository configuration changes as security-sensitive code, not merely as build maintenance.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Review dependency changes in pull requests

GitHub’s dependency review can show dependency additions, removals, and updates in a pull request and surface known vulnerabilities in changed dependencies. It does not block a merge automatically in every repository: configure the dependency-review action as a required check or use an organization-level required workflow if that is the intended policy. The behavior and enforcement options are described in GitHub’s dependency review documentation.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Dependency review is only as complete as the dependency information and supported ecosystems available to it. Maintain an inventory and identify dependencies that are missing from static manifests, generated outside them, or otherwise not represented in the dependency graph. GitHub outlines the broader feature set in its supply-chain security overview and offers guidance on securing code in the supply chain.

5. Reduce what GitHub Actions can do—and where compromise can persist

A workflow is executable code with access determined by its permissions, secrets, inputs, and runtime environment. Review those boundaries rather than treating a green run as proof that the workflow was safe.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Review permissions, secrets, and untrusted inputs

Check the permissions granted to GITHUB_TOKEN and individual workflows, the secrets made available to jobs, and how untrusted pull-request content or other external input is handled. Limit access to what a job needs, especially for workflows that process contributions or run code from outside the trusted branch. GitHub’s GitHub Actions security overview covers these risks, including script injection, compromised runners, and token security.

Assess runner isolation and cloud credentials

GitHub recommends that each build start in a fresh environment so that compromise does not persist into later builds. Review how runners are provisioned and discarded, with particular care for self-hosted runners that may retain state or have access to internal systems. Where workflows need cloud access, assess whether OpenID Connect (OIDC) can provide scoped, short-lived credentials instead of relying on long-lived cloud secrets. The right design depends on the environment and trust boundaries; GitHub’s build-system security guidance describes fresh build environments and provenance considerations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

6. Use attestations as provenance evidence, not a security guarantee

GitHub artifact attestations can connect a build artifact to context such as its workflow, repository, commit, environment, and triggering event, and can include an SBOM. This helps consumers evaluate where an artifact came from and how it was built. Its value depends on consumers verifying the attestation and applying their own trust policy; the existence of an attestation does not prove the source code or build process was benign.

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

GitHub puts the limitation plainly: “It is important to remember that artifact attestations are not a guarantee that an artifact is secure.” Read the details in the artifact attestations documentation.

7. Turn the response into an owned, testable baseline

After immediate response, convert lessons into controls with named owners. A compact follow-up register can make the work auditable without confusing policies that are enabled with risks that are actually covered.

  • Containment: record affected identities, repositories, workflows, and runners, plus the evidence behind each emergency action.
  • Access: track revocation or rotation of suspected credentials and review the systems and jobs that can use replacements.
  • Repository policy: document organization-wide settings, branch protection and review expectations, and approved exceptions.
  • Dependencies: identify supported and unsupported inventory sources, and decide how dependency-review results become merge requirements.
  • Builds: assign owners for workflow permissions, secret exposure, runner isolation, and cloud credential design.
  • Release evidence: define which consumers verify attestations and what trust policy they apply to the provenance.

Use the broader supply-chain code guidance and GitHub supply-chain security overview to align repository controls with dependency and release practices.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.