Remove step-security/harden-runner from all workflows - #263
Merged
Merged
Conversation
Drops 6 harden-runner step(s) across 6 file(s). Every one of them ran in `egress-policy: audit`, which only reports outbound calls after the fact - it blocks nothing. That left a third-party action with runner-level access wired into effectively every job, in exchange for telemetry nobody reads. The remaining hardening (SHA-pinned actions, explicit least-privilege `permissions:`) is unaffected. Removal was done by locating each `uses: step-security/harden-runner` line, deleting the whole step item around it, and then verifying the result by parsing the workflow before and after: the list of every remaining `uses:` had to be identical, and no job was allowed to end up with zero steps. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Removes
step-security/harden-runnerfrom every workflow in this repository.Why
Every occurrence ran with
egress-policy: audit. That mode only reports outbound network calls after the fact — it blocks nothing. The cost was a third-party action holding runner-level access in effectively every job of every workflow; the benefit was telemetry behind a dashboard. Not a trade worth keeping.The rest of the hardening posture is untouched: actions stay SHA-pinned with version comments, and every workflow keeps its explicit least-privilege
permissions:block.How, and how it was checked
Each
uses: step-security/harden-runnerline was located, the surrounding step item deleted as a whole, and the result verified by parsing the workflow YAML before and after the edit:uses:values had to be identical before and after,steps:list.The diff is deletions only — no line was added or reindented anywhere.
🤖 Generated with Claude Code