Skip to content

Bump version to 1.0.38 and upgrade uuid#215

Open
cx-atish-jadhav wants to merge 5 commits into
mainfrom
other/version-update
Open

Bump version to 1.0.38 and upgrade uuid#215
cx-atish-jadhav wants to merge 5 commits into
mainfrom
other/version-update

updated package-lock.json

eeebfa9
Select commit
Loading
Failed to load commit list.
StepSecurity Actions Security / StepSecurity Harden-Runner failed Jul 12, 2026 in 5m 26s

⚠️ Unexpected network calls from CI/CD runners

Harden-Runner has generated new alerts for GitHub Actions workflow runs in this pull request. These findings may indicate malicious activities or misconfigurations, so prompt analysis is recommended.

Details

Harden-Runner monitors all outbound traffic from each job at the DNS and network layers to ensure that CI/CD runners do not communicate with unauthorized destinations.
This reduces the risk of CI/CD secrets and source code being exfiltrated.

The following anomalous outbound network calls were detected.

Endpoint Workflow Workflow Run Insights status
kics.io ci.yml Insights URL ❌ Blocked
api-sca.checkmarx.net ci.yml Insights URL ❌ Blocked
api.openai.com ci.yml Insights URL ❌ Blocked

🔎 Potential next steps

Anomalous Network Call

To investigate and triage the detection, please follow the runbook at https://docs.stepsecurity.io/harden-runner/runbooks/anomalous-outbound-network-calls

📋 Monitored GitHub Actions workflow runs

The following GitHub Actions workflow runs were monitored as part of this pull request.

Workflow Run ID Unique Destinations Actions Used Detailed Insights
ci.yml 29193468493 17 2 View Insights
auto-merge-pr.yml 29193468502 - - Harden-Runner not enabled
dependabot-auto-merge.yml 29193468470 - - Harden-Runner not enabled
checkmarx-one-scan.yml 29193468498 6 2 View Insights

📚 Learn More

You can learn more about this GitHub check here