Skip to main content
Endor Labs Documentation home page
Search...
⌘K
Ask AI
⌘I
Documentation
Developers & API
Release Notes
Endor Labs Documentation home page
Search...
Navigation
Finding policies
GitHub Action policies
Introduction to Endor Labs
Overview
Getting started
Endor Labs user interface
Setup & Deployment
Overview
SCM Integrations
Scan from your IDE
Endor Outpost
MCP Server
Skills
CLI (endorctl)
CI/CD Integration
Inventory & Insights
Overview
Projects
Findings
Packages
Dashboards
Scan history
Dependencies
PR runs
SBOM
Notifications
Namespaces
Scan with Endor Labs
Overview
SCA (Software Composition Analysis)
Scan Profiles
SAST (Static Application Security Testing)
Secrets Detection
Container Scanning
Malware detection
AI Models
OSS Licenses
RSPM (Repository Security Posture Management)
Pull Request scans
Bazel
Working with monorepos
Risk Remediation
Overview
Upgrade impact analysis
Endor patches
Automated Pull Requests
Integrations
Overview
Set up custom package repositories
SCM Integrations
Webhooks
Package Firewall
Microsoft Defender for Cloud
Jira
Vanta
Data exporters
Email
Slack
Third-party integrations
Secure AI Coding
AI Security & Governance
MCP Server
Skills
AI Security Review
Agentic UI (AppSec Assistant)
AI Model Discovery
AI model scores
Platform Administration
Overview
Manage access to Endor Labs
Manage API keys
Policies
Overview
Finding policies
Overview
Container policies
License policies
RSPM policies
Open-source policies
SAST policies
Secret policies
GitHub Action policies
Exception policies
Action policies
Remediation policies
Tag projects
System settings
Namespaces
Proxy server settings
Best Practices
Overview
Branches and workflows
API key management
Scoping scans
Jira integration
GitHub Security Campaign
Build tools
Working with project filters
Working with dependency filters
Troubleshooting
Research Open Source Risks
Overview
Search for Open Source Packages
Endor Labs Vulnerability Database
Trust & Compliance
Trust & Compliance
Finding policies
GitHub Action policies
Learn about the out-of-the-box finding policies for GitHub Actions.
Endor Labs provides the following out-of-the-box policies that help you assess the security posture of GitHub Actions used in your software delivery process.
Policies for Repository Security Posture Management (RSPM) in GitHub
.
Policies for evaluating configuration settings in workflow file
.
See
Finding Policies
for details on how to
enable
,
disable
, or
edit
out-of-the-box policies.
Policies for RSPM
Policies for assessing configuration settings in workflow files
Secret policies
Previous
Exception policies
Next
⌘I
On this page
Policies for RSPM
Policies for assessing configuration settings in workflow files
Assistant
Responses are generated using AI and may contain mistakes.