ci: add harden-runner to all GitHub Actions workflows#755
Conversation
Add step-security/harden-runner v2.16.1 as the first step in every job across all 14 workflow files to improve supply chain security.
|
Is there a way to log these egress activities to Kosli? |
Good question. You mean as part of an attestation? |
@meekrosoft |
Code reviewNo issues found. Checked for bugs and CLAUDE.md compliance. 🤖 Generated with Claude Code - If this code review was useful, please react with 👍. Otherwise, react with 👎. |
Summary
step-security/harden-runnerv2.16.1 as the first step in every job across all 14 workflow filesfe104658747b27e96e4f7e80cd0a94068e53901degress-policy: auditto monitor outbound traffic without blocking