Code scanning alert #1443 (Hypatia, RE001) on #903: a job that references secrets.* runs without step-security/harden-runner. It fires on .github/workflows/roadmap-sync.yml:54 (the App private key passed to actions/create-github-app-token). No hypatia workflow uses harden-runner today, and it is not in .github/workflows/actions.lock, so adopting it is a repo-wide change rather than a one-file fix.
Acceptance criteria
Deferred from #903 under AGENTS §5c item 3 (a new scanner finding is an issue, not a blocker).
Code scanning alert #1443 (
Hypatia, RE001) on #903: a job that referencessecrets.*runs withoutstep-security/harden-runner. It fires on.github/workflows/roadmap-sync.yml:54(the App private key passed toactions/create-github-app-token). No hypatia workflow uses harden-runner today, and it is not in.github/workflows/actions.lock, so adopting it is a repo-wide change rather than a one-file fix.Acceptance criteria
step-security/harden-runner(SHA-pinned,egress-policy: auditfirst) is the first step of every job that referencessecrets.*, starting withroadmap-sync.yml.actions.lockgains the entry via targetedgh actions-lock <path>, andgh actions-lock --no-fix --verifyis clean for those workflows.Deferred from #903 under AGENTS §5c item 3 (a new scanner finding is an issue, not a blocker).