Skip to content

ci(macos): automate Developer ID signing + notarization in GitHub Actions#147

Merged
ashishkurmi merged 2 commits into
step-security:mainfrom
ashishkurmi:main
Jun 23, 2026
Merged

ci(macos): automate Developer ID signing + notarization in GitHub Actions#147
ashishkurmi merged 2 commits into
step-security:mainfrom
ashishkurmi:main

Merge branch 'main' into main

aa4cf43
Select commit
Loading
Failed to load commit list.
StepSecurity Actions Security / StepSecurity Harden-Runner succeeded Jun 23, 2026 in 4m 40s

⚠️ Unexpected network calls from CI/CD runners

Harden-Runner has generated new alerts for GitHub Actions workflow runs in this pull request. These findings may indicate malicious activities or misconfigurations, so prompt analysis is recommended.

Details

Harden-Runner monitors all outbound traffic from each job at the DNS and network layers to ensure that CI/CD runners do not communicate with unauthorized destinations.
This reduces the risk of CI/CD secrets and source code being exfiltrated.

Click here to approve this check run

The following anomalous outbound network calls were detected.

Endpoint Workflow Workflow Run Insights status description
xp.g.aaplimg.com:443 tests.yml Insights URL Approved by @akurmi@stepsecurity.io
proxy.safebrowsing.apple:443 tests.yml Insights URL Approved by @akurmi@stepsecurity.io

🔎 Potential next steps

Anomalous Network Call

To investigate and triage the detection, please follow the runbook at https://docs.stepsecurity.io/harden-runner/runbooks/anomalous-outbound-network-calls

📋 Monitored GitHub Actions workflow runs

The following GitHub Actions workflow runs were monitored as part of this pull request.

Workflow Run ID Unique Destinations Actions Used Detailed Insights
tests.yml 28001366581 20 4 View Insights
gosec.yml 28001366615 3 5 View Insights

📚 Learn More

You can learn more about this GitHub check here