Skip to content

RE001: adopt step-security/harden-runner in jobs that reference secrets (alert #1443, roadmap-sync.yml) #906

Description

@hyperpolymath

Code scanning alert #1443 (Hypatia, RE001) on #903: a job that references secrets.* runs without step-security/harden-runner. It fires on .github/workflows/roadmap-sync.yml:54 (the App private key passed to actions/create-github-app-token). No hypatia workflow uses harden-runner today, and it is not in .github/workflows/actions.lock, so adopting it is a repo-wide change rather than a one-file fix.

Acceptance criteria

  • step-security/harden-runner (SHA-pinned, egress-policy: audit first) is the first step of every job that references secrets.*, starting with roadmap-sync.yml.
  • actions.lock gains the entry via targeted gh actions-lock <path>, and gh actions-lock --no-fix --verify is clean for those workflows.
  • Alert #1443 closes as fixed.

Deferred from #903 under AGENTS §5c item 3 (a new scanner finding is an issue, not a blocker).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions