<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Chainguard Actions on</title><link>https://deploy-preview-3616--ornate-narwhal-088216.netlify.app/chainguard/actions/</link><description>Recent content in Chainguard Actions on</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Tue, 16 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://deploy-preview-3616--ornate-narwhal-088216.netlify.app/chainguard/actions/index.xml" rel="self" type="application/rss+xml"/><item><title>Chainguard Actions overview</title><link>https://deploy-preview-3616--ornate-narwhal-088216.netlify.app/chainguard/actions/overview/</link><pubDate>Thu, 18 Jun 2026 00:00:00 +0000</pubDate><guid>https://deploy-preview-3616--ornate-narwhal-088216.netlify.app/chainguard/actions/overview/</guid><description>&lt;p&gt;Chainguard Actions are a set of hardened drop-in replacements for popular GitHub Actions. Each action preserves the same inputs and outputs as the upstream version, but has been examined and revised to better protect your CI/CD pipelines from supply chain attacks. The only change in your workflow configuration is the name of the action in the &lt;code&gt;uses:&lt;/code&gt; line.&lt;/p&gt;
&lt;p&gt;Coverage spans GitHub first-party (&lt;code&gt;actions/*&lt;/code&gt;), cloud-provider (&lt;code&gt;aws-actions/*&lt;/code&gt;, &lt;code&gt;azure/*&lt;/code&gt;, &lt;code&gt;google-github-actions/*&lt;/code&gt;), Docker, HashiCorp, and security tools actions (Trivy, Grype, CodeQL, Semgrep), as well as a growing catalog of community actions.&lt;/p&gt;</description></item><item><title>Chainguard Actions telemetry and privacy</title><link>https://deploy-preview-3616--ornate-narwhal-088216.netlify.app/chainguard/actions/telemetry/</link><pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate><guid>https://deploy-preview-3616--ornate-narwhal-088216.netlify.app/chainguard/actions/telemetry/</guid><description>&lt;p&gt;Every Chainguard hardened action runs a best-effort &amp;ldquo;phone-home&amp;rdquo; pre-hook that records a usage event to &lt;code&gt;https://actions.enforce.dev/actions/v1/record&lt;/code&gt;. The hook is fire-and-forget, with a 2 second timeout that fails open, so it cannot break your build.&lt;/p&gt;
&lt;h2 id="what-we-collect" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;What we collect&lt;/span&gt;
&lt;a href="#what-we-collect" class="anchor" aria-label="Link to What we collect" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;What we collect depends on whether your workflow grants &lt;code&gt;id-token: write&lt;/code&gt;:&lt;/p&gt;</description></item></channel></rss>