
Enforcing Immutable Actions with Required Workflows
Using a required workflow to enforce that all GitHub Actions in your pull requests reference immutable releases, adding a supply chain security gate at the organization or enterprise level

Using a required workflow to enforce that all GitHub Actions in your pull requests reference immutable releases, adding a supply chain security gate at the organization or enterprise level

A walkthrough of the tools, workflows, and practices I use to maintain a growing collection of open source JavaScript GitHub Actions

How to include repository custom properties in GitHub Actions OIDC tokens to enable attribute-based access control to cloud environments

Using the new claims matching expression feature in Azure federated credentials to use wildcards with GitHub Actions OIDC subject claims

A GitHub Action to mirror clone repositories between GitHub environments (GitHub.com, EMU, and GitHub Enterprise Server) with support for visibility control, Actions disabling, and archiving

How to use Enterprise GitHub Apps to programmatically install third-party GitHub Marketplace apps across your enterprise organizations

A practical guide to building GitHub Agentic Workflows - AI-powered repository automation authored in Markdown, with real-world examples, troubleshooting tips, and lessons learned

A GitHub Action to sync repository settings, configuration files, and workflows across multiple repositories using a simple YAML config or custom property filtering

A utility to migrate GitHub Discussions between repositories, including categories, labels, comments, and replies

A comprehensive guide to using Enterprise GitHub Apps to programmatically install and manage applications across all organizations in your GitHub Enterprise