Obviously, by doing everything inside a container, where you control things. The GH action should only start the container, and pass it some env vars.