The linux runner has no git/node on host and rootless podman lacks namespace privileges. Use container: directive for every job: alpine for secrets (gitleaks binary), docker:latest for build (docker socket mounted by runner). Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>