Please report security vulnerabilities to info@stepsecurity.io
Security: step-security/harden-runner
Security
SECURITY.md
-
Egress Policy Bypass via DNS over HTTPS (DoH) in Harden-Runner (Community Tier)GHSA-46g3-37rh-v698 published
Mar 16, 2026 by varunsh-coderModerate -
Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)GHSA-cpmj-h4f6-r6pq published
Feb 7, 2026 by varunsh-coderModerate -
Egress Policy Bypass via DNS over TCP in Harden-Runner (Community Tier)GHSA-g699-3x6g-wm3g published
Mar 16, 2026 by varunsh-coderModerate -
Evasion of 'disable-sudo' policyGHSA-mxr3-8whj-j74r published
Apr 21, 2025 by varunsh-coderModerate -
Command injection weaknesses in `setup.ts` and `arc-runner.ts`GHSA-g85v-wf27-67xc published
Nov 18, 2024 by varunsh-coderLow
Learn more about advisories related to step-security/harden-runner in the GitHub Advisory Database