Skip to content

Enforce Harden-Runner deny-by-default egress policy #78

Description

@ChelseaKR

Controls: SEC-04.

Every workflow job currently runs Harden-Runner in audit mode. Derive the per-job endpoint allowlists from completed runs, switch to egress-policy: block, and verify all scheduled, PR, release, browser, container, and standards-fetch jobs remain green.

Done when no workflow remains in audit mode and the full CI/release workflow set passes.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions