Security Analysis for Github Actions

Modern software projects rely on automated pipelines (like GitHub Actions) to build, test, and deploy code. While these systems make development faster, small mistakes in their setup can create serious security risks, such as leaking sensitive data or allowing attackers to change how software behaves.
This project focuses on identifying and understanding these hidden risks. Today, there is no reliable collection of real-world examples showing how such misconfigurations happen, which makes it difficult to improve security tools.
To solve this, we will create a carefully curated dataset of GitHub Actions workflows, each labeled with known security issues. This dataset will be built using a mix of expert review and automated analysis tools developed by our industry partner, BoostSecurity.
The result will help researchers and companies better evaluate and improve security tools, making software development pipelines safer. Ultimately, this project aims to reduce real-world security risks and strengthen trust in modern software systems.

Faculty Supervisor:

Benoit Baudry

Student:

Partner:

Boost Security

Discipline:

Computer science

Sector:

Information and cultural industries

University:

Université de Montréal

Program:

Accelerate

Current openings

Find the perfect opportunity to put your academic skills and knowledge into practice!

Find Projects