Harden Runner

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

Cybersecurity & Ethical HackingTypeScriptApache-2.0

Abstract

Harden Runner is an open-source Cybersecurity & Ethical Hacking project. Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time. Learn how Harden-Runner works through the video below, which shows how it detected the tj-actions/changed-files compromise. View the interactive demo here. It is built using TypeScript, GitHub Actions. The complete source code is publicly available on GitHub under the Apache License 2.0, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.

1. Introduction

Learn how Harden-Runner works through the video below, which shows how it detected the tj-actions/changed-files compromise. View the interactive demo here.

StepSecurity Harden-Runner addresses this gap by providing security monitoring tailored for CI/CD runners, with support for Linux, Windows, and macOS runners. This approach brings CI/CD runners under the same level of security scrutiny as other critical systems, addressing a significant gap in the software supply chain.

Harden-Runner secures over 25 million CI/CD workflow runs every week, protecting thousands of pipelines, including those from popular open-source projects by Microsoft, Google, and CISA. See how top projects are using Harden-Runner and explore the insights: Who's using Harden-Runner?

2. Objective

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

This project demonstrates how TypeScript, GitHub Actions can be applied to a real-world Cybersecurity & Ethical Hacking problem.

4. Technology Stack

TypeScriptGitHub Actions

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • Node.js (LTS) and npm / yarn / pnpm
  • VS Code or any code editor
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/step-security/harden-runner.git
cd harden-runner

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add logging and alert notifications (email / Telegram)
  • Write a threat model document for the tool
  • Package it with Docker for safe lab testing

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Which threat or attack does this project defend against?
  2. What detection or protection technique is used and what are its limits?
  3. How are false positives and false negatives handled?
  4. Which cryptographic algorithms or security standards are involved?
  5. What legal and ethical rules apply when testing a tool like this?

9. Source Code & License

This project is developed by step-security and published on GitHub under the Apache License 2.0. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Cybersecurity & Ethical Hacking Internship