GitHub Actions CI/CD (AWS ECR + EC2)
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes official GitHub Actions from trusted organizations (actions/checkout, aws-actions/configure-aws-credentials, aws-actions/amazon-ecr-login) and well-known community actions (appleboy/ssh-action) to handle workflow logic.
- [COMMAND_EXECUTION]: Defines sophisticated deployment scripts executed on both the CI runner and remote EC2 instances. These scripts manage Docker container lifecycles, network-based health checks, and service orchestration.
- [SAFE]: Implements secure handling of sensitive data by writing AWS credentials and environment variables to temporary files created with
mktempand restricted withchmod 600. It ensures these files are deleted immediately after use via the shelltrapcommand. - [SAFE]: Incorporates a 'smoke test' phase that validates the health of a new container on a temporary port before promoting it to production, preventing the deployment of broken builds.
- [SAFE]: Employs a blue-green deployment strategy that renames and preserves the previous container version, enabling automatic rollback if the new version fails its health check.
Audit Metadata