awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
step-security avatar

step-security/harden-runner

0
View on GitHub↗
1,206 stars·106 forks·TypeScript·Apache-2.0·4 viewswww.stepsecurity.io↗

Harden Runner

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

Features

  • Supply Chain Security - Secures CI/CD runners by monitoring and restricting outbound network traffic.

Star history

Star history chart for step-security/harden-runnerStar history chart for step-security/harden-runner

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does step-security/harden-runner do?

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

What are the main features of step-security/harden-runner?

The main features of step-security/harden-runner are: Supply Chain Security.

What are some open-source alternatives to step-security/harden-runner?

Open-source alternatives to step-security/harden-runner include: aquasecurity/chain-bench — An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software… deislabs/ratify — Artifact Ratification Framework (CNCF Sandbox). denysvuika/supply-chain-inspector — A standalone, zero-dependency Node.js script for supply chain security analysis of npm dependencies. en/code-security. grafeas/kritis — Deploy-time Policy Enforcer for Kubernetes applications. anchore/syft — Syft is a software bill of materials generator, container image scanner, and software dependency catalog. It analyzes…

Open-source alternatives to Harden Runner

Similar open-source projects, ranked by how many features they share with Harden Runner.
  • aquasecurity/chain-benchaquasecurity avatar

    aquasecurity/chain-bench

    774View on GitHub↗

    An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.

    Go
    View on GitHub↗774
  • deislabs/ratifydeislabs avatar

    deislabs/ratify

    303View on GitHub↗

    Artifact Ratification Framework (CNCF Sandbox)

    Go
    View on GitHub↗303
  • denysvuika/supply-chain-inspectorDenysVuika avatar

    DenysVuika/supply-chain-inspector

    3View on GitHub↗

    A standalone, zero-dependency Node.js script for supply chain security analysis of npm dependencies.

    JavaScript
    View on GitHub↗3
  • anchore/syftanchore avatar

    anchore/syft

    8,399View on GitHub↗

    Syft is a software bill of materials generator, container image scanner, and software dependency catalog. It analyzes container images and filesystems to produce comprehensive inventories of installed packages and dependencies in standard formats. Additionally, it serves as a software attestation tool and an SBOM format converter. The project distinguishes itself through the ability to create cryptographically signed attestations for software inventories to ensure provenance and integrity. It also provides the capability to transform software bills of materials between different industry sche

    Gocontainerscyclonedxdocker
    View on GitHub↗8,399
See all 14 alternatives to Harden Runner→