Checkout No Persist Credentials
github-actions.checkout-no-persist-credentials
Flags actions/checkout steps that don't set persist-credentials: false. The default (true) stores GITHUB_TOKEN in .git/config, which leaks if the checkout directory is uploaded as an artifact (ArtiPACKED attacks, 2024).
Compatible Integrations
This guardrail works with the following integrations. Click to see how to use Checkout No Persist Credentials with each collector.
Enable This Guardrail
Add the parent policy to your lunar-config.yml to enable this guardrail.
policies:
- uses: github://earthly/lunar-lib/policies/github-actions@v1.0.5
include: [checkout-no-persist-credentials]
# with: ...
How This Guardrail Works
This guardrail is part of the GitHub Actions Security Guardrails policy. It evaluates data collected by integrations and produces a pass/fail check with actionable feedback.
When enabled, this check runs automatically on every PR and in AI coding workflows, providing real-time enforcement of your engineering standards.
Learn How Lunar Works →GitHub Actions Security Guardrails
This guardrail is part of the GitHub Actions Security Guardrails policy, which includes 6 guardrails for security and compliance.
Ready to Automate Your Standards?
See how Lunar can turn your AGENTS.md, engineering wiki, compliance docs, or postmortem action items into automated guardrails with our 100+ built-in guardrails.