Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github May 1, 2023

Bumps step-security/harden-runner from 1.5.0 to 2.3.1.

Release notes

Sourced from step-security/harden-runner's releases.

v2.3.1

What's Changed

Full Changelog: step-security/harden-runner@v2...v2.3.1

v2.3.0

What's Changed

Full Changelog: step-security/harden-runner@v2...v2.3.0

v2.2.1

What's Changed

Full Changelog: step-security/harden-runner@v2...v2.2.1

v2.2.1

What's Changed

Full Changelog: step-security/harden-runner@v2...v2.2.1

v2.2.0

What's Changed

  • Release v2.2.0 by @​varunsh-coder in step-security/harden-runner#245
    1. Added functionality that allows for skipping Harden Runner installation if any errors arise during the installation process.
    2. Updated Harden-Runner GitHub Action to use the latest version of the Harden Runner agent, which resolves three issues:
      • Addressed a bug that allowed calls to direct IP addresses not included in the allowed list when executing code in a docker image.
      • Enhanced annotations to eliminate false positives, specifically not showing false positive calls to docker.io

... (truncated)

Commits
  • 6b3083a Release v2.3.1 (#281)
  • 910b327 Merge pull request #270 from step-security/dependabot/github_actions/github/c...
  • 5f67082 Merge pull request #261 from step-security/dependabot/github_actions/actions/...
  • b3e3003 Merge pull request #265 from step-security/dependabot/github_actions/ossf/sco...
  • 5aebf47 Merge pull request #273 from step-security/dependabot/github_actions/codecov/...
  • d81767b Bump codecov/codecov-action from 3.1.1 to 3.1.2
  • 61a6a28 Bump github/codeql-action from 2.2.6 to 2.2.11
  • f8b2294 Merge pull request #268 from step-security/dependabot/github_actions/step-sec...
  • 3693a6b Bump step-security/harden-runner from 2.2.1 to 2.3.0
  • 49e89a7 Merge pull request #267 from step-security/varunsh-coder-patch-1
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 1.5.0 to 2.3.1.
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](step-security/harden-runner@2e205a2...6b3083a)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels May 1, 2023
@rajbos rajbos merged commit c247165 into master May 24, 2023
@dependabot dependabot bot deleted the dependabot/github_actions/step-security/harden-runner-2.3.1 branch May 24, 2023 08:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants