2026-10-11 18:01 UTC

Independent reproduction and provider responses will determine whether GitHub Actions OIDC tokens lacking restrictive audience constraints enable practical cross-service token reuse and require stronger CI identity controls.

state: expiredheat: lowuncertainty: highconvergesscott: mediumsoftware-supply-chain github-actions workload-identityGitHubwoodruffw

What is this?

GitHub Actions can issue short-lived OIDC tokens that workflows exchange for credentials at external services, replacing stored deployment secrets while shifting security responsibility to workflow integrity, trust policy, and relying-party claim validation. GitHub’s documentation says workflows and login actions can set custom `aud` claims, and that providers typically combine audience and subject claims to scope access. The supplied results do not independently demonstrate practical cross-service token reuse or establish woodruffw’s role; that remains a hypothesis requiring reproduction and responses from GitHub or affected providers.

Why it matters to Scott

The claimed cross-service reuse risk directly converges with Scott’s audience-bound capability-token and provenance position, and successful reproduction would provide a dated-receipts opportunity while bearing on credential controls in SiloOS. The supplied evidence does not yet establish exploitation or provider impact, so this remains a potentially consequential validation rather than a confirmed change Scott should act on.
ip:concept.capability-tokensip:framework.agent-provenance-stackdev:project.silo-osradar:concept.software-supply-chainradar:concept.agent-authenticationradar:concept.credential-isolationradar:person.github
queries asked of Scott's wikis
  • CI workload identity and audience-bound tokens
  • cross-service token reuse and confused-deputy risks
  • GitHub Actions supply-chain trust boundaries
  • federated credentials versus stored CI secrets
  • OIDC relying-party claim validation
  • least-privilege controls for CI/CD identities

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (3) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnGitHub Actions needs OIDC audience constraintswoodruffw10
🟧 echo.blog ⭐GitHub Actions needs OIDC audience constraints to prevent unsafe token use across relying services.woodruffw——
🟧 hnGitHub Actions needs OIDC audience constraintscimnine11

Interpretation history

Decision trace