Self-hosted runners inherit local trust
A build runner you host sits inside your network with whatever access that implies.
It also runs code from your repositories, which for a public or widely contributed project means running code from people you do not know. That combination, untrusted code on a trusted network, is exactly what you would avoid anywhere else, and it is the default arrangement for self-hosted CI.
More on CI/CD security
- A deployment pipeline is a privileged production pathIt goes straight over the gate
- Code review does not protect a compromised runnerNobody looked inside the machine
- Forked code should not automatically receive secretsThe belt does not ask who sent it
- Branch protection does not protect every release pathThe gate only guards its own road
- Deployment credentials should match deployment scopeOne bolt across all three
- Build logs can become secret leaksThe log is a page, and people read pages
