{"repo":"step-security/harden-runner","free":true,"listed":false,"github":"https://github.com/step-security/harden-runner","clone":"git clone https://github.com/step-security/harden-runner.git","description":"Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.","language":"TypeScript","stars":1250,"topics":["github-actions","actions","supply-chain-security","hardening","security-hardening","runners","egress-filtering","network-security","runtime-security"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"Harden-Runner Corporate laptops and production servers typically have robust security monitoring in place to reduce risk and meet compliance requirements. However, CI/CD runners, which handle sensitive information like secrets for cloud environments and create production builds, often lack such security measures. This oversight has led to significant supply chain attacks, including the SolarWinds and Codecov breaches. Traditional security monitoring and EDR solutions are ineffective for CI/CD runners due to their ephemeral nature. These tools also lack the necessary context to correlate events with specific workflow runs in a CI/CD environment. StepSecurity Harden-Runner addresses this gap by providing security monitoring tailored for CI/CD runners, with support for Linux, Windows, and macOS runners. This approach brings CI/CD runners under the same level of security scrutiny as other critical systems, addressing a significant gap in the software supply chain. Harden-Runner: Security Incidents Detected - Harden-Runner Detected the Compromised axios npm Package Dropping a Remote Access Trojan (backstage/backstage#33693, block/elasticgraph#1103) - Harden-Runner Detected the Trivy Compromise with Malicious v0.69.4 Release (k8gb-io/k8gb#2294) - Harden-Runner Detected the tj-actions/changed-files compromise (CVE-2025-30066) - Harden Runner Detected the Sha1-Hulud Supply Chain Attack in CNCF’s Backstage Repository - Harden-Runner Detected the NX Build System compromise - Harden-Run","default_branch":null,"files":null,"tree":[],"storefront":"/r/step-security","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/step-security/harden-runner/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}