Harden-CI: Protect your CI/CD A developer released Harden-CI, an open-source, agent-readable checklist that walks an AI coding agent through 16 steps to harden a CI/CD pipeline, from code to production. The project requires no installation: users point Claude Code, Codex, Antigravity or a similar agent at the harden-ci.secmy.app link while inside their repository, and the agent applies rules covering pinned actions and images, signed images, reviewed transitive dependencies, and protected main branches. The author says all changes happen locally under the user's review, with the source available on GitHub for cloning or modification. Your pipeline knows secrets, but who checks the pipe? CI/CD runs a code haveing access to keys / tokens and ither rights to publish, that is why Supply-chain attacks to dependencies / components are more often start not from application, but from a build process At the same time, the pipeline lives without any oversight. It may have tests, but they might not block new vulnerabilities or new code. Actions and images are linked to the latest tag. Images are not signed. Transitive dependencies have not been reviewed by anybody. And the main git branch is not protected from force pushes. Each of these items is small and easy to fix, but each of them is an open door for bad guys Harden-CI - it is only a file for your AI agent: Claude Code, Codex, Antigravity, or something like this. You should not install anything - just open your agent in your repository using a terminal or desktop/mobile app and send it the link to the website https://harden-ci.secmy.app/ https://harden-ci.secmy.app/ There are a few steps: How it looks: just send the link to your agent when you are in the project, and you will remember. See the picture below. Actually, that’s all. just make a decision and be happy During 16 steps, the add-on covers the whole chain from code to production It’s just because right now everyone has their own AI agent / AI assistant. It’s too easy to create a secure CI/CD. You should not be too lazy to create a really secure pipeline. And that is why I have created this page, just to help myself, my friends, and maybe you too. And of course, it’s possible to ignore some rules just because some of them are not applicable to your environment. That’s okay. You should not be absolutely aligned with the rules in this project. Even have 2-3 additional steps is better than nothing. if you absolutely disagree with some items/rules – the project is on GitHub https://github.com/SecH0us3/harden-ci . You may clone it, create your own list, or suggest changes Harden-CI https://harden-ci.secmy.app/ – the project is useful for solo developers or even for teams. If you do not have enough time for a manual audit and for thinking about best practices, let’s use this project. You should not need to create an additional subscription or service, or give access to a third party to set up and secure your pipeline. All changes happen on your machine, according to clear open rules and your review. It’s just a text description, and you can read each stage and rule yourself Do you have idea? Suggest it here https://github.com/SecH0us3/harden-ci https://github.com/SecH0us3/harden-ci