> ## Documentation Index
> Fetch the complete documentation index at: https://laravel-slipway.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Security model

> Secrets by name, least privilege, verified hosts, and no expression injection in generated scripts.

* **Secrets by name only.** The config holds names; the provider holds values. The scanner checks the config and the generated YAML, and a finding never contains the matched value.
* **Least privilege on GitHub.** `permissions: contents: read` by default, `persist-credentials: false` on checkout. Actions default to major-version tags (`actions/checkout@v4`), which are mutable. Run `slipway:pin` to resolve them to commit SHAs, paste the result into the `pins` driver option, and `strict` mode warns while any action is still unpinned.
* **No expression injection.** GitHub expressions inside `run` scripts are rejected. Secrets reach scripts only as step `env`, never interpolated into the command line.
* **Host keys are verified** for SSH deploys; there is no "accept any host" mode. SSH runs in batch mode with connection timeouts, and the deploy key is removed from the runner when the script ends.
* **Verified tooling on container providers.** On Bitbucket and GitLab the Composer installer is checked against its published checksum before it runs. Node.js is installed from the official tarball on nodejs.org after it is checked against the published `SHASUMS256.txt`. That protects against corrupt or tampered downloads; it is an integrity check, not a signature check. Use your own image through the `image` driver option if you need a fully pinned toolchain.
* **Validated inputs.** Hosts, users, paths and URL paths are validated before they reach a shell script.
* **Deterministic output** makes review and drift detection reliable.

Report vulnerabilities as described in [SECURITY.md](https://github.com/usamamuneerchaudhary/laravel-slipway/blob/main/SECURITY.md).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.