Controls: SEC-04.
Every workflow job currently runs Harden-Runner in audit mode. Derive the per-job endpoint allowlists from completed runs, switch to egress-policy: block, and verify all scheduled, PR, release, browser, container, and standards-fetch jobs remain green.
Done when no workflow remains in audit mode and the full CI/release workflow set passes.
Controls: SEC-04.
Every workflow job currently runs Harden-Runner in audit mode. Derive the per-job endpoint allowlists from completed runs, switch to
egress-policy: block, and verify all scheduled, PR, release, browser, container, and standards-fetch jobs remain green.Done when no workflow remains in audit mode and the full CI/release workflow set passes.