mirror of
https://github.com/step-security/harden-runner.git
synced 2026-06-06 13:47:06 +00:00
Pull-mirror of github.com/step-security/harden-runner
- TypeScript 100%
| .github/workflows | ||
| dist | ||
| src | ||
| .gitignore | ||
| action.yml | ||
| LICENSE | ||
| package-lock.json | ||
| package.json | ||
| README.md | ||
| SECURITY.md | ||
| tsconfig.json | ||
Policy-based Runtime Security for GitHub Actions
First-of-its-kind patent-pending technology that automatically correlates outbound traffic with each step of a workflow.
- Add this code to your GitHub Actions workflow file as the first step.
steps:
- uses: step-security/harden-runner@v1
with:
egress-policy: audit
- uses: actions/checkout@v2
- In the workflow logs, you will see a link to security insights and recommendations.
- Click on the link (example link).
- Add the recommended outbound endpoints to your workflow file, and only traffic to these endpoints will be allowed.
steps:
- uses: step-security/harden-runner@v1
with:
allowed-endpoints:
github.com:443
nodejs.org:443
registry.npmjs.org:443
- uses: actions/checkout@v2