Skip to content

Remove step-security/harden-runner from all workflows - #263

Merged
TomTonic merged 1 commit into
mainfrom
chore/remove-harden-runner
Sep 6, 2026
Merged

TomTonic merged 1 commit into
mainfrom
chore/remove-harden-runner

Conversation

@TomTonic

@TomTonic TomTonic commented Sep 6, 2026

Copy link
Copy Markdown
Owner

Removes step-security/harden-runner from every workflow in this repository.

Why

Every occurrence ran with egress-policy: audit. That mode only reports outbound network calls after the fact — it blocks nothing. The cost was a third-party action holding runner-level access in effectively every job of every workflow; the benefit was telemetry behind a dashboard. Not a trade worth keeping.

The rest of the hardening posture is untouched: actions stay SHA-pinned with version comments, and every workflow keeps its explicit least-privilege permissions: block.

How, and how it was checked

Each uses: step-security/harden-runner line was located, the surrounding step item deleted as a whole, and the result verified by parsing the workflow YAML before and after the edit:

  • the list of all remaining uses: values had to be identical before and after,
  • no job was allowed to be left with an empty steps: list.

The diff is deletions only — no line was added or reindented anywhere.

🤖 Generated with Claude Code

Drops 6 harden-runner step(s) across 6 file(s). Every one of them
ran in `egress-policy: audit`, which only reports outbound calls after the
fact - it blocks nothing. That left a third-party action with runner-level
access wired into effectively every job, in exchange for telemetry nobody
reads. The remaining hardening (SHA-pinned actions, explicit least-privilege
`permissions:`) is unaffected.

Removal was done by locating each `uses: step-security/harden-runner` line,
deleting the whole step item around it, and then verifying the result by
parsing the workflow before and after: the list of every remaining `uses:`
had to be identical, and no job was allowed to end up with zero steps.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@TomTonic
TomTonic merged commit 7f89108 into main Sep 6, 2026
6 checks passed
@TomTonic
TomTonic deleted the chore/remove-harden-runner branch September 6, 2026 21:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant