step-security/harden-runner

step-security/harden-runner

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

GitHubGithub Repository

775 stars

Node.js

Node Action

Updated 1 day ago

GitHub Actions security score

step-security/harden-runner

Score

10/10

License

Apache License 2.0

Maintained

Maintained by StepSecurity

Vulnerabilities

0 existing vulnerabilities detected

Branch protection

Branch protection is maximal on development and all release branches

Manual code review

Upstream changes are reviewed before merging

Secure publishing

Reproducible builds with SBOM and provenance

Signed commits

All commits are signed

Automated security tools

Findings from tools are triaged and fixed before each change

Popular

Used by StepSecurity enterprise customers

Security Policy

security policy file detected