Your pipeline knows secrets, but who checks the pipe?
CI/CD runs a code haveing access to keys / tokens and ither rights to publish, that is why Supply-chain attacks to dependencies / components are more often start not from application, but from a build process
At the same time, the pipeline lives without any oversight. It may have tests, but they might not block new vulnerabilities or new code. Actions and images are linked to the latest tag. Images are not signed. Transitive dependencies have not been reviewed by anybody. And the main git branch is not protected from force pushes. Each of these items is small and easy to fix, but each of them is an open door for bad guys
Harden-CI - it is only a file for your AI agent: Claude Code, Codex, Antigravity, or something like this. You should not install anything - just open your agent in your repository using a terminal or desktop/mobile app and send it the link to the website https://harden-ci.secmy.app/
There are a few steps:
How it looks: just send the link to your agent when you are in the project, and you will remember. See the picture below. Actually, that’s all. just make a decision and be happy
During 16 steps, the add-on covers the whole chain from code to production
It’s just because right now everyone has their own AI agent / AI assistant. It’s too easy to create a secure CI/CD. You should not be too lazy to create a really secure pipeline. And that is why I have created this page, just to help myself, my friends, and maybe you too. And of course, it’s possible to ignore some rules just because some of them are not applicable to your environment. That’s okay. You should not be absolutely aligned with the rules in this project. Even have 2-3 additional steps is better than nothing. if you absolutely disagree with some items/rules – the project is on GitHub. You may clone it, create your own list, or suggest changes
Harden-CI – the project is useful for solo developers or even for teams. If you do not have enough time for a manual audit and for thinking about best practices, let’s use this project. You should not need to create an additional subscription or service, or give access to a third party to set up and secure your pipeline. All changes happen on your machine, according to clear open rules and your review. It’s just a text description, and you can read each stage and rule yourself
Do you have idea? Suggest it here https://github.com/SecH0us3/harden-ci