Hamburger Cross Icon
github-actions.no-secrets-inherit

Flags secrets: inherit in reusable workflow calls. This passes ALL repository and org secrets to the called workflow, violating least-privilege. Workflows should explicitly pass only needed secrets.

secrets inherit reusable least-privilege security

Compatible Integrations

This guardrail works with the following integrations. Click to see how to use No Secrets Inherit with each collector.

Enable This Guardrail

Add the parent policy to your lunar-config.yml to enable this guardrail.

📄 lunar-config.yml
policies:
  - uses: github://earthly/lunar-lib/policies/github-actions@v1.0.5
    include: [no-secrets-inherit]
    # with: ...

How This Guardrail Works

This guardrail is part of the GitHub Actions Security Guardrails policy. It evaluates data collected by integrations and produces a pass/fail check with actionable feedback.

When enabled, this check runs automatically on every PR and in AI coding workflows, providing real-time enforcement of your engineering standards.

Learn How Lunar Works →
1
↓ Integrations Gather Data
Collectors extract metadata from code, CI pipelines, tool outputs, and scans
2
{ } Centralized as JSON
All data merged into each component's unified metadata document
3
✓ This Guardrail Checks Current
No Secrets Inherit runs and provides pass/fail feedback

Configuration Options

These inputs can be configured in your lunar-config.yml to customize how the parent policy (and this guardrail) behaves.

Input Required Default Description
exempt_jobs Required — Workflow jobs exempt from `checkout-no-persist-credentials`, for a risk that has been reviewed and accepted. Entries are `<workflow-file>:<job-id>`, separated by newlines or commas: ```yaml with: exempt_jobs: | # accepted TICKET-123 — repo-scoped 1h token, no artifact upload .github/workflows/publish.yaml:push ``` The workflow matches the collected path or its bare filename; the job id is the key under `jobs:`. `#` comments are ignored, so the rationale can sit next to the entry it explains. An exemption never turns a finding into a pass. Findings that are not exempt still fail; the check resolves to `skip`, naming each exempted job, only when every finding it made was exempted. An entry that cannot be parsed fails the check without exempting anything. An entry naming a workflow the component has but a job it does not define is reported as stale. An entry whose workflow file the component does not have at all is ignored — one policy entry is normally shared by every component in its scope.
GitHub Actions Security Guardrails

GitHub Actions Security Guardrails

This guardrail is part of the GitHub Actions Security Guardrails policy, which includes 6 guardrails for security and compliance.

View Policy

Ready to Automate Your Standards?

See how Lunar can turn your AGENTS.md, engineering wiki, compliance docs, or postmortem action items into automated guardrails with our 200+ built-in guardrails.

Works with any process
check AI agent rules & prompt files
check Post-mortem action items
check Security & compliance policies
check Testing & quality requirements
Auto-ID My Guardrails
Paste your AGENTS.md or manual process doc and get guardrails in minutes
Book a Demo