Skip to content

[rc1-prep] Add step-security/harden-runner to ko-publish for egress audit #315

Description

@trilamsr

Per docs/v1-rc1-operational-gaps.md §1 SLSA L3, remediation step 2.

Work: add step-security/harden-runner@<sha> to the ko-publish job in .github/workflows/release.yml with an egress allowlist pinned to proxy.golang.org, sum.golang.org, gcr.io, ghcr.io, fulcio.sigstore.dev, rekor.sigstore.dev.

Note: on ubuntu-latest, harden-runner audits egress rather than blocking it. This delivers an attestable network-trace artifact alongside SLSA provenance.

Acceptance: every release-tag run uploads a step-security/harden-runner audit artifact showing zero egress to undeclared endpoints.

Effort: S.

Metadata

Metadata

Assignees

No one assigned

    Labels

    rc1-prepv1.0-rc1 preparation tasks per docs/v1-rc1-operational-gaps.md

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions