From 6d7ef151130886d085485286c05d6cf56d8ab3b8 Mon Sep 17 00:00:00 2001 From: Tom Tonic Date: Sun, 6 Sep 2026 23:22:20 +0200 Subject: [PATCH] Remove the step-security/harden-runner step from all workflows Drops 6 harden-runner step(s) across 6 file(s). Every one of them ran in `egress-policy: audit`, which only reports outbound calls after the fact - it blocks nothing. That left a third-party action with runner-level access wired into effectively every job, in exchange for telemetry nobody reads. The remaining hardening (SHA-pinned actions, explicit least-privilege `permissions:`) is unaffected. Removal was done by locating each `uses: step-security/harden-runner` line, deleting the whole step item around it, and then verifying the result by parsing the workflow before and after: the list of every remaining `uses:` had to be identical, and no job was allowed to end up with zero steps. Co-Authored-By: Claude Opus 5 --- .github/workflows/codeql.yml | 5 ----- .github/workflows/coverage.yml | 5 ----- .github/workflows/dependency-review.yml | 5 ----- .github/workflows/fuzz.yml | 5 ----- .github/workflows/lint.yml | 5 ----- .github/workflows/scorecard.yml | 5 ----- 6 files changed, 30 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 7dd2618..34bba68 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -40,11 +40,6 @@ jobs: # Learn more about CodeQL language support at https://aka.ms/codeql-docs/language-support steps: - - name: Harden Runner - uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1 - with: - egress-policy: audit - - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 diff --git a/.github/workflows/coverage.yml b/.github/workflows/coverage.yml index 3ea873a..ceb89b5 100644 --- a/.github/workflows/coverage.yml +++ b/.github/workflows/coverage.yml @@ -10,11 +10,6 @@ jobs: permissions: contents: write steps: - - name: Harden Runner - uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1 - with: - egress-policy: audit - - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 6464d41..a41eb54 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -16,11 +16,6 @@ jobs: dependency-review: runs-on: ubuntu-latest steps: - - name: Harden Runner - uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1 - with: - egress-policy: audit - - name: Checkout Repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 diff --git a/.github/workflows/fuzz.yml b/.github/workflows/fuzz.yml index de7d634..6e1cd7f 100644 --- a/.github/workflows/fuzz.yml +++ b/.github/workflows/fuzz.yml @@ -12,11 +12,6 @@ jobs: fuzz: runs-on: ubuntu-latest steps: - - name: Harden Runner - uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1 - with: - egress-policy: audit - - name: Checkout Repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index b5d75e5..a85f086 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -15,11 +15,6 @@ jobs: # To report GitHub Actions status checks statuses: write steps: - - name: Harden Runner - uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1 - with: - egress-policy: audit - - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 9cfd909..dd0d949 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -31,11 +31,6 @@ jobs: # actions: read steps: - - name: Harden Runner - uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1 - with: - egress-policy: audit - - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: