Chainguard Actions overview
Learn how Chainguard Actions provides hardened drop-in replacements for popular GitHub Actions to protect your CI/CD …
For the complete documentation index, see llms.txt.
Every Chainguard hardened action runs a best-effort “phone-home” pre-hook that records a usage event to https://actions.enforce.dev/actions/v1/record. The hook is fire-and-forget, with a 2 second timeout that fails open, so it cannot break your build.
We collect this data for two reasons:
What we collect depends on whether your workflow grants id-token: write:
id-token: write: we record your repository name, a timestamp, and an “unverified” flag.id-token: write: the hook mints a GitHub OIDC token scoped to the actions.chainguard.dev audience and sends it so we can verify the record. From that token we store metadata: repository, actor, ref, sha, workflow path, repository visibility, and run identifiers.The hook never grants itself id-token: write. It only uses the permission if your workflow already grants it. If you would rather we receive only your repository name, do not grant id-token: write to that job.
The token is a short-lived, audience-locked GitHub OIDC token. Because it is locked to the actions.chainguard.dev audience, it cannot be used against GitHub, a cloud provider, or any other service. The underlying ACTIONS_ID_TOKEN_REQUEST_TOKEN never leaves the runner; it is used locally only to mint the audience-scoped token.
Learn how Chainguard Actions provides hardened drop-in replacements for popular GitHub Actions to protect your CI/CD …
What to check when the Chainguard Console or a security advisory says a CVE is fixed, but your vulnerability scanner …
How to use the Chainguard Terraform provider to create overlays and bind them to specific tags of a Custom Assembly …
How to use chainctl to create overlays and bind them to specific tags of a Custom Assembly repository.
Upload an agent skill for hardening, track the job, browse results in user folders, and review the report before …
Last updated: 2026-09-28 14:00