# GitHub Actions: who can change the build tool?

https://thiago.limaesilvatecnologia.com.br/en/artigos/actions-third-party/

Published: 2026-09-12

Pipeline dependencies deserve code-level scrutiny.

Content produced with AI assistance for Thiago Silva’s website. Independent editorial analysis; it does not represent clients or employers.

Reading-path month: March 2026

Collection published on September 12, 2026. Months organize the reading path; they are not earlier publication dates.

A short architecture article. The technical reference supports the topic; hypothetical scenarios and assessment proposals are editorial analysis, not accounts of personal implementations.

## The architecture decision

A reused action introduces behavior into delivery. Ask not only whether it works, but who can change what runs during the next release.

## Practical application

Editorial proposal: inventory actions by origin, reference and available permissions. In a hypothetical pipeline, assess formatting separately from artifact publication. Dependency impact depends on execution context.

## How to verify

Select an update and document review, testing and rollback. The team should know which implementation ran, not just its friendly name. This record supports incident response and prevents reuse convenience from becoming unlimited trust.

## Sources

- [OWASP — GitHub Actions Security Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/GitHub_Actions_Security_Cheat_Sheet.html). Accessed: 2026-09-12.

[Profile: Thiago Silva | Cyber Architect](https://thiago.limaesilvatecnologia.com.br/en/perfil/)
