# Where Does actions/checkout Store Credentials to Prevent Audit Log Exposure?

> Discover where actions/checkout stores credentials securely in a temporary Git config file to prevent audit log exposure. Learn about the placeholder technique.

- Repository: [GitHub Actions/checkout](https://github.com/actions/checkout)
- Tags: internals
- Published: 2026-08-30

---

**The action stores authentication tokens in a temporary Git configuration file located in the runner's `RUNNER_TEMP` directory, using a placeholder technique to prevent the secret from appearing in process creation audit logs.**

The `actions/checkout` repository implements a sophisticated credential management system to protect sensitive tokens during GitHub Actions workflows. By avoiding command-line arguments and instead using a dedicated configuration file strategy, the action ensures that authentication secrets remain invisible to standard operating system audit mechanisms that log process arguments.

## Temporary File Creation in RUNNER_TEMP

The credential storage mechanism begins in [`src/git-auth-helper.ts`](https://github.com/actions/checkout/blob/main/src/git-auth-helper.ts), where the helper class establishes a dedicated path for sensitive data. On line 46, a comment reserves the file location, and the system later obtains the full path via the `getCredentialsConfigPath()` method (lines 46-48).

This file resides exclusively within the runner's temporary directory (`RUNNER_TEMP`), ensuring it never persists on the host filesystem beyond the job's execution. The action deliberately chooses this location to isolate credentials from the repository workspace and global Git configuration files.

## The Placeholder Technique for Audit Log Safety

To prevent audit log exposure, `actions/checkout` first writes a decoy value to the temporary configuration file before inserting the real token. Between lines 33 and 38, the code executes `git config` commands to store a placeholder entry reading `AUTHORIZATION: basic ***`.

This approach satisfies a critical security requirement: **process creation audit logs** on Windows and Linux systems capture the full command-line arguments of spawned processes. Because the initial `git config` command contains only asterisks rather than the actual secret, audit trails record harmless placeholder text while the real credential remains concealed.

## Token Injection and Git Configuration Linkage

After the placeholder file exists, the action performs direct file manipulation to insert the authentic token. Between lines 42 and 57, the code replaces the placeholder with the Base64-encoded authentication string `x-access-token:<authToken>`. This direct file write bypasses the shell and process monitors entirely, leaving no trace in system logs.

Finally, the action links this temporary credentials file to the repository's Git configuration using conditional includes. Lines 68 through 79 configure `includeIf.gitdir:…` entries that instruct Git to load the temporary file only when operating within the specific repository directory. This ensures the credentials apply solely to the intended checkout context without polluting global Git settings.

## Controlling Credential Persistence

You can manage this behavior through the `persist-credentials` input parameter. By default, the action sets this to `true`, creating the temporary credentials file for subsequent workflow steps to use.

```yaml

# Default behavior: credentials stored safely in RUNNER_TEMP

- uses: actions/checkout@v4
  with:
    token: ${{ secrets.GITHUB_TOKEN }}
    persist-credentials: true

```

To disable credential storage entirely and prevent the temporary file creation:

```yaml
- uses: actions/checkout@v4
  with:
    token: ${{ secrets.PAT }}
    persist-credentials: false

```

The token value itself originates from [`src/input-helper.ts`](https://github.com/actions/checkout/blob/main/src/input-helper.ts), which retrieves the input via `core.getInput('token')` and stores it in the `authToken` property defined in [`src/git-source-settings.ts`](https://github.com/actions/checkout/blob/main/src/git-source-settings.ts).

## Key Implementation Files

Several source files orchestrate this security model:

- **[`src/git-auth-helper.ts`](https://github.com/actions/checkout/blob/main/src/git-auth-helper.ts)** – Implements the temporary credentials file, placeholder handling, and `includeIf` linkage mechanisms described above.
- **[`src/git-source-settings.ts`](https://github.com/actions/checkout/blob/main/src/git-source-settings.ts)** – Defines the `authToken` property structure used to transport the secret between components.
- **[`src/input-helper.ts`](https://github.com/actions/checkout/blob/main/src/input-helper.ts)** – Retrieves the `token` input from workflow definitions using `@actions/core`.
- **[`src/git-command-manager.ts`](https://github.com/actions/checkout/blob/main/src/git-command-manager.ts)** – Executes the low-level `git config` commands that initially write the placeholder to the temporary file.

## Summary

- **actions/checkout** stores authentication tokens in a temporary Git configuration file inside `RUNNER_TEMP`, not in the repository or global Git config.
- A **placeholder technique** using `AUTHORIZATION: basic ***` prevents the real token from appearing in process creation audit logs during initial file setup.
- The actual token (`x-access-token:<authToken>`) is injected via direct file manipulation after the placeholder is established.
- **Conditional includes** (`includeIf.gitdir`) link the temporary credentials file only to the specific repository context.
- Set **`persist-credentials: false`** to disable the temporary file creation entirely.

## Frequently Asked Questions

### What is RUNNER_TEMP in GitHub Actions?

`RUNNER_TEMP` is an environment variable pointing to a temporary directory specific to the current job execution. Files stored here are automatically cleaned up when the job completes, making it ideal for storing sensitive intermediate data like authentication credentials that should not persist on the runner host.

### Why does actions/checkout use a placeholder before writing the real token?

The placeholder technique prevents the secret from appearing in operating system audit logs that record process command-line arguments. By first writing `AUTHORIZATION: basic ***` via `git config`, followed by direct file replacement of the real token, the action ensures audit trails capture only the masked placeholder while the actual credential enters the file through file-system operations invisible to process monitors.

### How can I prevent actions/checkout from storing credentials?

Set the `persist-credentials` input to `false` in your workflow step configuration. This prevents the action from creating the temporary Git configuration file entirely, though you must then manually configure authentication for any subsequent Git operations in your workflow.

### What file format stores the credential in the temporary directory?

The credential is stored in a standard Git configuration file format (INI-style) with an `http.extraheader` entry containing the Base64-encoded authorization header. The file is referenced via Git's `includeIf` conditional include mechanism, ensuring it only applies to the specific repository directory matching the `gitdir` pattern.