Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Removing action runner hardening #712

Merged
merged 1 commit into from
Jan 29, 2024
Merged

Removing action runner hardening #712

merged 1 commit into from
Jan 29, 2024

Conversation

therealryan
Copy link
Collaborator

#161 upgraded our actions to lock down unexpected network and file access. We've never been able to actually activate that hardening as our testing's use of multicast sockets tripped over the restrictions but there is no mechanism to allow-list it.

We're now getting warnings on our action run about the node version that the plugin uses, which prompted me to stop waiting for a fix on step-security/harden-runner#228

For the time being let's remove that plugin from our actions.

Copy link

sonarcloud bot commented Jan 29, 2024

Quality Gate Passed Quality Gate passed

Kudos, no new issues were introduced!

0 New issues
0 Security Hotspots
No data about Coverage
No data about Duplication

See analysis details on SonarCloud

@therealryan therealryan merged commit 9b2d320 into main Jan 29, 2024
9 checks passed
@therealryan therealryan deleted the rm_stepsec branch January 29, 2024 08:47
@therealryan therealryan mentioned this pull request Jan 29, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant