Skip to content

chore(ci): add Step Security Harden Runner to workflows in audit mode#15934

Open
Joibel wants to merge 1 commit intoargoproj:mainfrom
Joibel:harden
Open

chore(ci): add Step Security Harden Runner to workflows in audit mode#15934
Joibel wants to merge 1 commit intoargoproj:mainfrom
Joibel:harden

Conversation

@Joibel
Copy link
Copy Markdown
Member

@Joibel Joibel commented Apr 15, 2026

Motivation

With the threats of AI attacking CI, use step security in line with argoproj/argo-cd#27168.

Modifications

Adds step-security/harden-runner in audit mode to all GitHub Actions Linux jobs. Supports disabling via the repository variable disable_harden_runner (set to "true"), following the approach taken in argoproj/argo-cd#27168.

Verification

CI only - lets see if it catches fire.

Documentation

Not required

Adds step-security/harden-runner in audit mode to all GitHub Actions
Linux jobs. Supports disabling via the repository variable
`disable_harden_runner` (set to "true"), following the approach taken
in argoproj/argo-cd#27168.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Alan Clucas <alan@clucas.org>
@Joibel Joibel marked this pull request as draft April 15, 2026 12:43
@Joibel Joibel marked this pull request as ready for review April 15, 2026 12:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant