Harden-Runner CI/CD Security Agent for GitHub Actions
Harden-Runner by StepSecurity is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity in real-time, detecting supply chain attacks such as the tj-actions and Codecov compromises.
Installation
Requirements and caveats from upstream:
Basic usage or getting-started notes:
This guide walks you through the steps to set up and use Harden-Runner in your CI/CD workflows. For more details, refer to the official documentation.
Step 1: Add Harden-Runner to Your Workflow
Extracted from upstream docs: https://raw.githubusercontent.com/step-security/harden-runner/HEAD/README.md