step-security/harden-runner
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time. observed · 2026-08-28
Health v2 · maintenance only
98/100
- Activity 97
- Release rhythm 98
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 15.0
- age_days: 1770
- days_rel: 18
- days_push: 18
- n_releases_24m: 31
Adoption not part of the score
1258 stars · 111 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Harden-Runner is a CI/CD security agent that acts like an EDR for GitHub Actions runners, monitoring network egress, file integrity, and process activity in real time. It detects compromised dependencies and malicious workflow behavior, and has caught several real-world supply chain attacks such as the tj-actions/changed-files and axios npm compromises.
Use cases
- detect compromised npm packages in CI builds
- monitor network egress from GitHub Actions runners
- prevent secrets exfiltration during CI/CD pipelines
- harden GitHub Actions workflows against supply chain attacks
- get alerts when a build step downloads from unexpected domains
- audit file and process activity on CI runners
- comply with software supply chain security requirements
When to choose
- you run builds on GitHub Actions and want runtime security monitoring
- you need to detect malicious dependencies or exfiltration attempts in CI
- you want an EDR-like agent tailored to ephemeral CI/CD runners
- you need egress filtering and file integrity monitoring for build pipelines
When to avoid
- you need security monitoring for developer laptops or production servers rather than CI runners
- you use CI systems other than GitHub Actions without the enterprise plan
- you only need static dependency scanning rather than runtime detection
Facets
service · maturity active
security monitoring ci-cd alerting tracing security developer-tools windows cloud self-hosted github-actions supply-chain-security edr egress-filtering ebpf runtime-security ci-cd-security hardening devops automation linux macos docker
6 sources
- readme: https://github.com/step-security/harden-runner · fetched 2026-08-28 · 1017afc51747
- homepage: https://www.stepsecurity.io · fetched 2026-08-29 · 0a0874ddb60a
- site_page: https://docs.stepsecurity.io/ · fetched 2026-08-29 · a138bdcbe557
- site_page: https://www.stepsecurity.io/pricing · fetched 2026-08-29 · c862f2ab5ddf
- site_page: https://www.stepsecurity.io/company · fetched 2026-08-29 · 04ef9d864fd7
- site_page: https://www.stepsecurity.io/blog · fetched 2026-08-29 · 6978d7225bb9
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| step-security/harden-runner | main | 98 |
For agents
markdown · JSON · MCP: product_card(name="step-security/harden-runner")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem