The build runs on a managed CI runner
build/runs-on-hosted-ci@v1
The artifact was built on a CI platform, not on someone's workstation, so the build is attributable and repeatable.
| Id | build/runs-on-hosted-ci |
| Version | v1 |
| Category | build |
| Default severity | error |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | env |
Collectors
This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.
| Collector | Gathers | Inputs it is given |
|---|---|---|
env | Where the build is running: which CI provider, whether the runner is hosted or self hosted, what triggered it, and whether federated credentials are available to it. | none |
The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.
Configuration
{
"guardrails": {
"failOn": "error",
"checks": [
{
"use": "build/runs-on-hosted-ci@v1",
"severity": "error",
"with": {
"allowSelfHosted": "true"
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
allowSelfHosted | Whether a self-hosted runner counts. Set it to false if you only trust the provider's own hosted fleet to build a release. | true | GUARDRAIL_INPUT_ALLOWSELFHOSTED |
How to fix
Build releasable artifacts in your pipeline, not on a laptop. A workstation build has no attributable identity, no clean environment and no record, and those are what SLSA Build L2 expects a build platform to provide.
If running guardrails on a workstation is legitimate, exempt it locally instead of removing the guardrail:
buildnote guardrails --only git/conventional-commitsMore in build
build/dependency-updates-configured. The repository configures a tool that opens dependency updates, so upgrades arrive as pull requests you can review instead of as a chore nobody has time for.build/gradle-version-floor. The Gradle version the wrapper pins is at or above the floor your team sets, so the build runs on a toolchain that is still supported.build/wrapper-distribution-verified. The Gradle wrapper pins the checksum of the distribution it downloads, so nobody can swap the toolchain underneath the build.