Ross ROSS = Recommend OSS · open-source software intelligence for agents

step-security/harden-runner

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time. observed · 2026-08-28

github.com/step-security/harden-runner · homepage · TypeScript · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

98/100

  • Activity 97
  • Release rhythm 98
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 15.0
  • age_days: 1770
  • days_rel: 18
  • days_push: 18
  • n_releases_24m: 31

Full methodology

Adoption not part of the score

1258 stars · 111 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Harden-Runner is a CI/CD security agent that acts like an EDR for GitHub Actions runners, monitoring network egress, file integrity, and process activity in real time. It detects compromised dependencies and malicious workflow behavior, and has caught several real-world supply chain attacks such as the tj-actions/changed-files and axios npm compromises.

Use cases

  • detect compromised npm packages in CI builds
  • monitor network egress from GitHub Actions runners
  • prevent secrets exfiltration during CI/CD pipelines
  • harden GitHub Actions workflows against supply chain attacks
  • get alerts when a build step downloads from unexpected domains
  • audit file and process activity on CI runners
  • comply with software supply chain security requirements

When to choose

  • you run builds on GitHub Actions and want runtime security monitoring
  • you need to detect malicious dependencies or exfiltration attempts in CI
  • you want an EDR-like agent tailored to ephemeral CI/CD runners
  • you need egress filtering and file integrity monitoring for build pipelines

When to avoid

  • you need security monitoring for developer laptops or production servers rather than CI runners
  • you use CI systems other than GitHub Actions without the enterprise plan
  • you only need static dependency scanning rather than runtime detection

Facets

service · maturity active

security monitoring ci-cd alerting tracing security developer-tools windows cloud self-hosted github-actions supply-chain-security edr egress-filtering ebpf runtime-security ci-cd-security hardening devops automation linux macos docker

6 sources

Member repositories

RepositoryRoleHealth v2
step-security/harden-runnermain98

For agents

markdown · JSON · MCP: product_card(name="step-security/harden-runner")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem