step-security / secure-repo

Orchestrate GitHub Actions Security
https://app.stepsecurity.io
GNU Affero General Public License v3.0
255 stars 41 forks source link

Don't add harden-runner to jobs running on Windows #2471

Open tippmar-nr opened 2 months ago

tippmar-nr commented 2 months ago

Since harden-runner doesn't support Windows, it seems a bit silly for the secure-repo tool to add the harden-runner action to every job running on a Windows runner.

https://github.com/step-security-bot/newrelic-dotnet-agent/commit/a2461358f729292db4a0bdfc5b23474f48a7f02d

varunsh-coder commented 2 months ago

Thanks @tippmar-nr for the feedback!

Agree with your point. We are actually working on harden-runner for windows as well, and that should be released in the next few months.