Skip to content

ci: apply security best practices #2530

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Apply security best practicesSigned-off-by: StepSecurity Bot <bot@ste…

3571016
Select commit
Loading
Failed to load commit list.
Open

ci: apply security best practices #2530

Apply security best practicesSigned-off-by: StepSecurity Bot <bot@ste…
3571016
Select commit
Loading
Failed to load commit list.
StepSecurity Actions Security / StepSecurity Harden-Runner succeeded Jun 5, 2025 in 2m 46s

No anomalous activity on CI/CD runners

No new Harden-Runner detections for this pull request.

Details

Harden-Runner monitors all outbound traffic from each job at the DNS and network layers to ensure that CI/CD runners do not communicate with unauthorized destinations.
This reduces the risk of CI/CD secrets and source code being exfiltrated.

📋 Monitored GitHub Actions workflow runs

The following GitHub Actions workflow runs were monitored as part of this pull request.

Workflow Run ID Unique Destinations Actions Used Detailed Insights
codeql.yml 15471104004 6 3 View Insights
test.yml 15471103995 8 4 View Insights

📚 Learn More

You can learn more about this GitHub check here