Konubinix' opinionated web of thoughts

Github Self-Hosted Runners Security

Fleeting

github

We recommend that you only use self-hosted runners with private repositories. This is because forks of your public repository can potentially run dangerous code on your self-hosted runner machine by creating a pull request that executes the code in a workflow.

https://docs.github.com/en/actions/hosting-your-own-runners/about-self-hosted-runners