{"repo":"koalalab-inc/bolt","free":true,"listed":false,"github":"https://github.com/koalalab-inc/bolt","clone":"git clone https://github.com/koalalab-inc/bolt.git","description":"Secure GitHub actions with 1 line of code","language":"JavaScript","stars":38,"topics":["cicd","egress-filtering","egress-gateway","github-actions","hardening","owasp-top-10","supply-chain-security","devops","devsecops","sdlc-security"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"BOLT:Secure GitHub Actions Runtime with 1 line of code BOLT is an egress-filter and runtime security tool for your GitHub Actions environment. Usage Add this step to jobs in your GitHub workflow file(s) to secure your runner: BOLT is packaged as a GitHub Action, which means you can easily add it to your workflows and start controlling the egress traffic from your pipelines. [!NOTE] Supports both public and private repositories Why use BOLT? Ther aftermath of Solarwinds breach has led to an increase in software supply chain attacks. CI/CD pipelines are the infrastructure of which the software is built, they are the keys to the cloud kingdom, and are high-leverage attack surfaces. OWASP top 10 CI/CD and CISA+NSA's joint guidance on defending CI/CD are really great starting points to understand the threat vectors surrounding CI/CD. An adaption of the same for GitHub environment would look a little like: and specifically focussing on the CI runtime threat vectors(and their solution): BOLT covers both the threat vectors by 1. Transparent Egress filtering mechanism which allows traffic only to trusted domains 2. Detection of actions with Sudo permissions to prevent against file-tampering during build time. How to use Bolt - Video Introduction https://github.com/koalalab-inc/bolt/assets/2908925/7bf51186-e673-4bed-9b56-ae15c7ab9154 Usage You can start using Bolt by adding the koalalab-inc/bolt action as the first step in the jobs you want to monitor. The action will install and start","default_branch":null,"files":null,"tree":[],"storefront":"/r/koalalab-inc","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/koalalab-inc/bolt/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}