Skip to content

Guardrails / build

The build runs on a managed CI runner ​

build/runs-on-hosted-ci@v1

The artifact was built on a CI platform, not on someone's workstation, so the build is attributable and repeatable.

Idbuild/runs-on-hosted-ci
Versionv1
Categorybuild
Default severityerror
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsenv

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
envWhere the build is running: which CI provider, whether the runner is hosted or self hosted, what triggered it, and whether federated credentials are available to it.none

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "build/runs-on-hosted-ci@v1",
              "severity": "error",
              "with": {
                  "allowSelfHosted": "true"
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
allowSelfHostedWhether a self-hosted runner counts. Set it to false if you only trust the provider's own hosted fleet to build a release.trueGUARDRAIL_INPUT_ALLOWSELFHOSTED

How to fix ​

Build releasable artifacts in your pipeline, not on a laptop. A workstation build has no attributable identity, no clean environment and no record, and those are what SLSA Build L2 expects a build platform to provide.

If running guardrails on a workstation is legitimate, exempt it locally instead of removing the guardrail:

bash
buildnote guardrails --only git/conventional-commits

More in build ​

  • build/dependency-updates-configured. The repository configures a tool that opens dependency updates, so upgrades arrive as pull requests you can review instead of as a chore nobody has time for.
  • build/gradle-version-floor. The Gradle version the wrapper pins is at or above the floor your team sets, so the build runs on a toolchain that is still supported.
  • build/wrapper-distribution-verified. The Gradle wrapper pins the checksum of the distribution it downloads, so nobody can swap the toolchain underneath the build.

All 4 build guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412