Do you do this for public repos? GitHub Actions is strongly not recommended for non-private. Struggling to have good security policies in place for a deployment I'm doing...
In the past, people could modify the GitHub action workflow and run crypto miners on the agents.
But since GitHub changed the default for PR where the actions aren't run anymore that killed that attack vector.
By who? Why?
Looks like I'd better do some research. :)