Skip to content

fix: tighten MCP config redaction and config-scan symlink handling - #191

Open
swarit-stepsecurity wants to merge 2 commits into
step-security:mainfrom
swarit-stepsecurity:swarit/chore/wt/vapt-cleanup
Open

fix: tighten MCP config redaction and config-scan symlink handling#191
swarit-stepsecurity wants to merge 2 commits into
step-security:mainfrom
swarit-stepsecurity:swarit/chore/wt/vapt-cleanup

fix(configaudit): don't follow symlinks during project-scope config s…

5fe8cbd
Select commit
Loading
Failed to load commit list.
StepSecurity Actions Security / StepSecurity Harden-Runner succeeded Aug 15, 2026 in 3m 3s

No anomalous activity on CI/CD runners

No new Harden-Runner detections for this pull request.

Details

Harden-Runner monitors all outbound traffic from each job at the DNS and network layers to ensure that CI/CD runners do not communicate with unauthorized destinations.
This reduces the risk of CI/CD secrets and source code being exfiltrated.

📋 Monitored GitHub Actions workflow runs

The following GitHub Actions workflow runs were monitored as part of this pull request.

Workflow Run ID Unique Destinations Actions Used Detailed Insights
tests.yml 31871773006 18 4 View Insights
msi-smoke.yml 31871772997 5 4 View Insights
gosec.yml 31871773028 3 5 View Insights

📚 Learn More

You can learn more about this GitHub check here