fix: Resolve security vulnerabilities #136
Merged
StepSecurity Actions Security / StepSecurity Harden-Runner
succeeded
Apr 21, 2026 in 5m 3s
No anomalous activity on CI/CD runners
No new Harden-Runner detections for this pull request.
Details
Harden-Runner monitors all outbound traffic from each job at the DNS and network layers to ensure that CI/CD runners do not communicate with unauthorized destinations.
This reduces the risk of CI/CD secrets and source code being exfiltrated.
📋 Monitored GitHub Actions workflow runs
The following GitHub Actions workflow runs were monitored as part of this pull request.
| Workflow | Run ID | Unique Destinations | Actions Used | Detailed Insights |
|---|---|---|---|---|
| example-build-artifacts.yml | 24707237620 | 19 | 4 | View Insights |
| check-markdown.yml | 24707237601 | 18 | 2 | View Insights |
| example-firefox.yml | 24707237560 | 8 | 3 | View Insights |
| claude_review.yml | 24707237684 | 1 | 4 | View Insights |
| example-quiet.yml | 24707237574 | 11 | 2 | View Insights |
| example-wait-on.yml | 24707237617 | 15 | 2 | View Insights |
| example-install-only.yml | 24707237590 | 8 | 3 | View Insights |
| example-start.yml | 24707237600 | 10 | 2 | View Insights |
| example-basic-pnpm.yml | 24707237636 | 23 | 4 | View Insights |
| example-yarn-modern.yml | 24707237564 | 13 | 3 | View Insights |
| example-edge.yml | 24707237582 | 12 | 2 | View Insights |
| example-custom-ci-build-id.yml | 24707237606 | - | - | Harden-Runner not enabled |
| check-dist.yml | 24707237618 | 4 | 3 | View Insights |
| example-custom-command.yml | 24707237602 | 11 | 2 | View Insights |
| example-install-command.yml | 24707237613 | 11 | 2 | View Insights |
| example-webpack.yml | 24707237596 | 10 | 2 | View Insights |
| example-chrome.yml | 24707237589 | 12 | 3 | View Insights |
| example-debug.yml | 24707237610 | 11 | 2 | View Insights |
| example-basic.yml | 24707237593 | 28 | 3 | View Insights |
| example-yarn-modern-pnp.yml | 24707237588 | 13 | 3 | View Insights |
| example-chrome-for-testing.yml | 24707237623 | 11 | 3 | View Insights |
| example-yarn-classic.yml | 24707237575 | 11 | 3 | View Insights |
| dependency-review.yml | 24707237607 | 3 | 3 | View Insights |
| codeql.yml | 24707237630 | 3 | 3 | View Insights |
| example-env.yml | 24707237587 | 10 | 2 | View Insights |
| auto_cherry_pick.yml | 24707237664 | - | - | Harden-Runner not enabled |
| example-start-and-pnpm-workspaces.yml | 24707237566 | 10 | 4 | View Insights |
| example-node-versions.yml | 24707237628 | 13 | 3 | View Insights |
| example-recording.yml | 24707237619 | - | - | Harden-Runner not enabled |
| example-start-and-yarn-workspaces.yml | 24707237612 | 11 | 2 | View Insights |
| example-config.yml | 24707237591 | 10 | 2 | View Insights |
| example-docker.yml | 24707237608 | - | - | Harden-Runner not enabled |
| example-component-test.yml | 24707237597 | 10 | 2 | View Insights |
📚 Learn More
You can learn more about this GitHub check here
Loading