Where Does actions/checkout Store Credentials to Prevent Audit Log Exposure?

The action stores authentication tokens in a temporary Git configuration file located in the runner's RUNNER_TEMP directory, using a placeholder technique to prevent the secret from appearing in process creation audit logs.

The actions/checkout repository implements a sophisticated credential management system to protect sensitive tokens during GitHub Actions workflows. By avoiding command-line arguments and instead using a dedicated configuration file strategy, the action ensures that authentication secrets remain invisible to standard operating system audit mechanisms that log process arguments.

Temporary File Creation in RUNNER_TEMP

The credential storage mechanism begins in src/git-auth-helper.ts, where the helper class establishes a dedicated path for sensitive data. On line 46, a comment reserves the file location, and the system later obtains the full path via the getCredentialsConfigPath() method (lines 46-48).

This file resides exclusively within the runner's temporary directory (RUNNER_TEMP), ensuring it never persists on the host filesystem beyond the job's execution. The action deliberately chooses this location to isolate credentials from the repository workspace and global Git configuration files.

The Placeholder Technique for Audit Log Safety

To prevent audit log exposure, actions/checkout first writes a decoy value to the temporary configuration file before inserting the real token. Between lines 33 and 38, the code executes git config commands to store a placeholder entry reading AUTHORIZATION: basic ***.

This approach satisfies a critical security requirement: process creation audit logs on Windows and Linux systems capture the full command-line arguments of spawned processes. Because the initial git config command contains only asterisks rather than the actual secret, audit trails record harmless placeholder text while the real credential remains concealed.

Token Injection and Git Configuration Linkage

After the placeholder file exists, the action performs direct file manipulation to insert the authentic token. Between lines 42 and 57, the code replaces the placeholder with the Base64-encoded authentication string x-access-token:<authToken>. This direct file write bypasses the shell and process monitors entirely, leaving no trace in system logs.

Finally, the action links this temporary credentials file to the repository's Git configuration using conditional includes. Lines 68 through 79 configure includeIf.gitdir:… entries that instruct Git to load the temporary file only when operating within the specific repository directory. This ensures the credentials apply solely to the intended checkout context without polluting global Git settings.

Controlling Credential Persistence

You can manage this behavior through the persist-credentials input parameter. By default, the action sets this to true, creating the temporary credentials file for subsequent workflow steps to use.


# Default behavior: credentials stored safely in RUNNER_TEMP

- uses: actions/checkout@v4
  with:
    token: ${{ secrets.GITHUB_TOKEN }}
    persist-credentials: true

To disable credential storage entirely and prevent the temporary file creation:

- uses: actions/checkout@v4
  with:
    token: ${{ secrets.PAT }}
    persist-credentials: false

The token value itself originates from src/input-helper.ts, which retrieves the input via core.getInput('token') and stores it in the authToken property defined in src/git-source-settings.ts.

Key Implementation Files

Several source files orchestrate this security model:

  • src/git-auth-helper.ts – Implements the temporary credentials file, placeholder handling, and includeIf linkage mechanisms described above.
  • src/git-source-settings.ts – Defines the authToken property structure used to transport the secret between components.
  • src/input-helper.ts – Retrieves the token input from workflow definitions using @actions/core.
  • src/git-command-manager.ts – Executes the low-level git config commands that initially write the placeholder to the temporary file.

Summary

  • actions/checkout stores authentication tokens in a temporary Git configuration file inside RUNNER_TEMP, not in the repository or global Git config.
  • A placeholder technique using AUTHORIZATION: basic *** prevents the real token from appearing in process creation audit logs during initial file setup.
  • The actual token (x-access-token:<authToken>) is injected via direct file manipulation after the placeholder is established.
  • Conditional includes (includeIf.gitdir) link the temporary credentials file only to the specific repository context.
  • Set persist-credentials: false to disable the temporary file creation entirely.

Frequently Asked Questions

What is RUNNER_TEMP in GitHub Actions?

RUNNER_TEMP is an environment variable pointing to a temporary directory specific to the current job execution. Files stored here are automatically cleaned up when the job completes, making it ideal for storing sensitive intermediate data like authentication credentials that should not persist on the runner host.

Why does actions/checkout use a placeholder before writing the real token?

The placeholder technique prevents the secret from appearing in operating system audit logs that record process command-line arguments. By first writing AUTHORIZATION: basic *** via git config, followed by direct file replacement of the real token, the action ensures audit trails capture only the masked placeholder while the actual credential enters the file through file-system operations invisible to process monitors.

How can I prevent actions/checkout from storing credentials?

Set the persist-credentials input to false in your workflow step configuration. This prevents the action from creating the temporary Git configuration file entirely, though you must then manually configure authentication for any subsequent Git operations in your workflow.

What file format stores the credential in the temporary directory?

The credential is stored in a standard Git configuration file format (INI-style) with an http.extraheader entry containing the Base64-encoded authorization header. The file is referenced via Git's includeIf conditional include mechanism, ensuring it only applies to the specific repository directory matching the gitdir pattern.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →