关于操作策略
通过操作策略,可以控制工作流在组织和存储库中的运行方式 GitHub Actions 。 可以在设置的新 “策略 ”部分中 GitHub Actions 配置操作策略,这与现有的 常规 设置不同。
操作策略在企业、组织和存储库级别可用。
操作策略当前包含一种类型的策略:工作流执行保护。 GitHub 计划随着时间的推移添加更多策略。
关于工作流执行保护机制
使用工作流执行保护可以定义允许列表,该列表控制谁可以触发 GitHub Actions 工作流以及允许哪些事件运行它们。 工作流执行保护附带两种规则类型:事件和执行组件。 GitHub 计划随着时间的推移添加更多规则。
工作流执行保护基于 GitHub 规则集框架构建,因此你从规则集中已知道的目标也适用于此处。 可以使用规则集应用保护,并使用存储库自定义属性将其限定为特定存储库。 有关规则集的详细信息,请参阅 关于规则集。 For more information, see About Actions policies.
注意
GitHub has added a default policy that will block the pull_request_target event in public repositories. This policy will be enforced on November 2, 2026. See 安全地使用 pull_request_target.
Preparing to add protections
Like rulesets, workflow execution protections layer with other protections in the same repository, organization, or enterprise.
Rather than creating one large policy per account, we recommend creating multiple clearly defined policies and layering protections across account levels. Enterprise owners can create protections at the enterprise level for broad, non-negotiable policies. Organization owners and repository administrators can then add to these restrictions.
For each policy you define, think about:
-
Which organizations or repositories your protection will target. For example, open source repositories may need tighter restrictions on who can trigger workflows. You can target repositories by factors like visibility, deployment status, or custom property.
- Deployment status comes from an organization's linked artifacts page. If this is an important factor, make sure you're uploading deployment records when an artifact is deployed. See 关于关联的项目.
- To create and assign custom properties, see 管理组织中存储库的自定义属性.
-
Which workflows will be protected. For example, workflows that deploy production code might need a certain level of protection, but less sensitive automations may not need the same level of protection. You can scope policies to specific workflow paths or required workflows.
-
Who should be able to run these workflows in the repositories you're targeting. This might be users with a certain role, selected bot accounts, or a specific team. Consider grouping these users in an organization or enterprise team so they can be easily contacted and referenced across multiple rulesets. See 创建组织团队 or 创建企业团队.
Creating a workflow execution policy
First, create a new Actions policy for the account level you're working at.
In a repository or organization:
- Click the Settings tab.
- In the left sidebar, under Actions, click Policies.
In an enterprise:
- Click the Policies tab.
- In the left sidebar, click Actions, then Policies.
提示
To manage policies programmatically, see REST API endpoints for GitHub Actions policies.
Configuring the policy
Next, create a new policy.
- Choose a name for the policy.
- Choose an enforcement status. If you select Evaluate (GitHub Enterprise Cloud only), you will be able to monitor when users would hit the restriction in policy insights.
- Target your desired workflows, organizations, or repositories.
- Configure the following workflow execution protections.
Restrict actors
By default, every user with write access to a repository can trigger workflows. Actor rules let you separate who contributes code from who runs your CI, so you can grant a contributor write access without granting them the ability to execute workflows.
Only the allowed actors will be able to run the specified workflows in the targeted repository. If you also restrict events, these users will only be able to trigger workflows with the allowed events. Non-allowed actors will not be able to run the specified workflows at all.
GitHub features are exempt from these restrictions for the built-in processes that they run on GitHub Actions. However, if you have created workflows that need to be run by the identity associated with a GitHub feature, such as dependabot[bot], then this identity must be added as an allowed actor.
Restrict events
Event rules control which events are permitted, such as push, pull_request, pull_request_target, and workflow_dispatch.
Evaluating policies
You can view policy insights to see workflow runs that have been blocked (for active policies) or would have been blocked (for "evaluate" policies). This is a good way to check that policies are working as intended and not causing unnecessary friction.
To view insights, click the Policy insights page. You'll find this directly under the page for GitHub Actions policies in your repository, organization, or enterprise sidebar.