Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you want an easy solution for GitHub Actions security, check out Garnet.ai (formerly listen.dev). They were built for GitHub first. And it’s free for single projects - https://dashboard.listen.dev/.


Does it allow to integrate directly into the action runner?


Yes, its a one step integration into your workflow file, typically before the steps you want to monitor eg. build, test if you don't want to see everything happening in your runner host. It has worked pretty well with ubuntu-latest and stock Linux runners from GH out of the box.


The integration basically wraps *jibril - a single binary linux edr which allows for detection and enforcement in the runner

https://jibril.sh




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: