[{"data":1,"prerenderedAt":4},["ShallowReactive",2],{"readme:fence":3},"\u003Ch1>Fence 🛡️\u003C\u002Fh1>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fopenai\u002Ffence\u002Factions\u002Fworkflows\u002Flint.yml\" rel=\"nofollow ugc noopener\">\u003Cimg src=\"https:\u002F\u002Fgithub.com\u002Fopenai\u002Ffence\u002Factions\u002Fworkflows\u002Flint.yml\u002Fbadge.svg\" alt=\"lint\" \u002F>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fopenai\u002Ffence\u002Factions\u002Fworkflows\u002Ftest.yml\" rel=\"nofollow ugc noopener\">\u003Cimg src=\"https:\u002F\u002Fgithub.com\u002Fopenai\u002Ffence\u002Factions\u002Fworkflows\u002Ftest.yml\u002Fbadge.svg\" alt=\"test\" \u002F>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fopenai\u002Ffence\u002Factions\u002Fworkflows\u002Fbuild.yml\" rel=\"nofollow ugc noopener\">\u003Cimg src=\"https:\u002F\u002Fgithub.com\u002Fopenai\u002Ffence\u002Factions\u002Fworkflows\u002Fbuild.yml\u002Fbadge.svg\" alt=\"build\" \u002F>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fopenai\u002Ffence\u002Factions\u002Fworkflows\u002Facceptance.yml\" rel=\"nofollow ugc noopener\">\u003Cimg src=\"https:\u002F\u002Fgithub.com\u002Fopenai\u002Ffence\u002Factions\u002Fworkflows\u002Facceptance.yml\u002Fbadge.svg\" alt=\"acceptance\" \u002F>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fopenai\u002Ffence\u002Factions\u002Fworkflows\u002Faction-acceptance.yml\" rel=\"nofollow ugc noopener\">\u003Cimg src=\"https:\u002F\u002Fgithub.com\u002Fopenai\u002Ffence\u002Factions\u002Fworkflows\u002Faction-acceptance.yml\u002Fbadge.svg\" alt=\"action acceptance\" \u002F>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fopenai\u002Ffence\u002Factions\u002Fworkflows\u002Faction-drift-canary.yml?query=branch%3Amain+event%3Aschedule\" rel=\"nofollow ugc noopener\">\u003Cimg src=\"https:\u002F\u002Fgithub.com\u002Fopenai\u002Ffence\u002Factions\u002Fworkflows\u002Faction-drift-canary.yml\u002Fbadge.svg?branch=main&amp;event=schedule\" alt=\"released action \u002F ubuntu-24.04 + ubuntu-latest\" \u002F>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fopenai\u002Ffence\u002Factions\u002Fworkflows\u002Faction-acceptance-ubuntu-latest.yml?query=branch%3Amain+event%3Aschedule\" rel=\"nofollow ugc noopener\">\u003Cimg src=\"https:\u002F\u002Fgithub.com\u002Fopenai\u002Ffence\u002Factions\u002Fworkflows\u002Faction-acceptance-ubuntu-latest.yml\u002Fbadge.svg?branch=main&amp;event=schedule\" alt=\"main \u002F ubuntu-latest\" \u002F>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fopenai\u002Ffence\u002Factions\u002Fworkflows\u002Fintegration.yml\" rel=\"nofollow ugc noopener\">\u003Cimg src=\"https:\u002F\u002Fgithub.com\u002Fopenai\u002Ffence\u002Factions\u002Fworkflows\u002Fintegration.yml\u002Fbadge.svg\" alt=\"integration\" \u002F>\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>A GitHub Action for hardening CI\u002FCD pipelines with bounded egress filtering and runner lockdown.\u003C\u002Fp>\n\u003Cp>\u003Cimg src=\"https:\u002F\u002Fraw.githubusercontent.com\u002Fopenai\u002Ffence\u002FHEAD\u002Fdocs\u002Fassets\u002Ffence.png\" alt=\"Fence\" \u002F>\u003C\u002Fp>\n\u003Ch2>Quick Start ⚡\u003C\u002Fh2>\n\u003Cp>Add Fence as the first step in a supported GitHub-hosted Linux job:\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-yaml\">- uses: openai\u002Ffence@&lt;commit-sha&gt; # pin@vX.Y.Z\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>This starts Fence in \u003Ccode>block\u003C\u002Fcode> mode with an empty user \u003Ccode>allowlist\u003C\u002Fcode> on a GitHub-hosted x64 job using \u003Ccode>ubuntu-24.04\u003C\u002Fcode> or \u003Ccode>ubuntu-latest\u003C\u002Fcode>. Replace \u003Ccode>&lt;commit-sha&gt;\u003C\u002Fcode> with the full \u003Ccode>action_commit\u003C\u002Fcode> value and \u003Ccode>vX.Y.Z\u003C\u002Fcode> with the tag from the same release; release notes provide the ready-to-copy line with a Dependabot-friendly \u003Ccode># pin@vX.Y.Z\u003C\u002Fcode> comment. \u003Ccode>main\u003C\u002Fcode> is source-only and does not contain a runnable production bundle. Put Fence before checkout and any other steps you want it to constrain.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Read more:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fopenai\u002Ffence\u002Fblob\u002FHEAD\u002Fdocs\u002Fgetting-started.md\" rel=\"nofollow ugc noopener\">Getting started with Fence\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch2>Examples 🧪\u003C\u002Fh2>\n\u003Cp>Start with a complete job that activates Fence before checkout:\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-yaml\">jobs:\n  test:\n    runs-on: ubuntu-24.04\n    steps:\n      - uses: openai\u002Ffence@&lt;fence-commit-sha&gt;\n      - uses: actions\u002Fcheckout@&lt;checkout-commit-sha&gt;\n      - run: script\u002Ftest\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Run in audit mode first to see what would need review before enabling blocking:\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-yaml\">- uses: openai\u002Ffence@&lt;commit-sha&gt;\n  with:\n    mode: audit\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The audit summary suggests allowlist entries for observed hostnames and direct IPv4 or IPv6 destinations.\u003C\u002Fp>\n\u003Cp>Allow GitHub artifact uploads, including GitHub Pages deployments and GitHub Actions caches, while keeping other network restrictions in place:\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-yaml\">- uses: openai\u002Ffence@&lt;commit-sha&gt;\n  with:\n    allow_github_artifacts: true\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>This setting is off by default. It permits up to four exact GitHub-shaped results-storage accounts on HTTPS and makes artifact storage available to the job. Enable it only when the workflow needs artifacts: later steps may also use the permitted accounts to upload data. Fence does not allow all Azure Blob Storage.\u003C\u002Fp>\n\u003Cp>Allow one or more HTTPS hostnames:\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-yaml\">- uses: openai\u002Ffence@&lt;commit-sha&gt;\n  with:\n    allowlist: |\n      api.example.com\n      artifacts.example.com\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Allow custom TCP, UDP, or CIDR destinations:\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-yaml\">- uses: openai\u002Ffence@&lt;commit-sha&gt;\n  with:\n    allowlist: |\n      registry.example.com:8443\n      udp:\u002F\u002Fdns.example.com:53\n      cidr 192.0.2.0\u002F24 udp 123\n      cidr 2001:db8::\u002F64 tcp 443\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Keep Docker\u002Fcontainer access available while still applying network restrictions and disabling passwordless sudo:\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-yaml\">- uses: openai\u002Ffence@&lt;commit-sha&gt;\n  with:\n    container_policy: unsafe_preser\n\u003C\u002Fcode>\u003C\u002Fpre>\n",1785125871426]