Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update step-security/harden-runner action to v2.7.1 #22

Merged
merged 1 commit into from
Apr 30, 2024
Merged

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Apr 29, 2024

Mend Renovate

This PR contains the following updates:

Package Type Update Change
step-security/harden-runner action patch v2.7.0 -> v2.7.1

Release Notes

step-security/harden-runner (step-security/harden-runner)

v2.7.1

Compare Source

What's Changed

Release v2.7.1 by @​varunsh-coder, @​h0x0er, @​ashishkurmi in https://github.com/step-security/harden-runner/pull/397
This release:

  • Improves the capability to inspect outbound HTTPS traffic on GitHub-hosted and self-hosted VM runners
  • Updates README to add link to case study video on how Harden-Runner detected a supply chain attack on a Google open-source project
  • Addresses minor bugs

Full Changelog: step-security/harden-runner@v2.7.0...v2.7.1


Configuration

📅 Schedule: Branch creation - "every 1 hours every weekday" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot merged commit 360352f into main Apr 30, 2024
3 checks passed
@renovate renovate bot deleted the renovate/all branch April 30, 2024 00:07
sbtaylor15 added a commit that referenced this pull request May 23, 2024
* fix div by 0
Signed-off-by: Steve Taylor <[email protected]>

* cleanup lint warnings
Signed-off-by: Steve Taylor <[email protected]>

* Bump version: 9.3.225 → 9.3.226
Signed-off-by: Steve Taylor <[email protected]>

* handle '' in total committers cnt
Signed-off-by: Steve Taylor <[email protected]>

* Bump version: 9.3.226 → 9.3.227
Signed-off-by: Steve Taylor <[email protected]>

* look for openapi.json etc
Signed-off-by: Steve Taylor <[email protected]>

* Bump version: 9.3.227 → 9.3.228
Signed-off-by: Steve Taylor <[email protected]>

* add signature and signed-off-by
Signed-off-by: Steve Taylor <[email protected]>

* Bump version: 9.3.228 → 9.3.229
Signed-off-by: Steve Taylor <[email protected]>

* add signature and signed-off-by
Signed-off-by: Steve Taylor <[email protected]>

* Bump version: 9.3.229 → 9.3.230
Signed-off-by: Steve Taylor <[email protected]>

* escape < >
Signed-off-by: Steve Taylor <[email protected]>

* Bump version: 9.3.230 → 9.3.231
Signed-off-by: Steve Taylor <[email protected]>

* fix IMAGE_REPO var
Signed-off-by: Steve Taylor <[email protected]>

* Bump version: 9.3.231 → 9.3.232
Signed-off-by: Steve Taylor <[email protected]>

* run kubectl to get imagetags
Signed-off-by: Steve Taylor <[email protected]>

* Bump version: 9.3.232 → 9.3.233
Signed-off-by: Steve Taylor <[email protected]>

* fix div by 0
Signed-off-by: Steve Taylor <[email protected]>

* cleanup lint warnings
Signed-off-by: Steve Taylor <[email protected]>

* handle '' in total committers cnt
Signed-off-by: Steve Taylor <[email protected]>

* look for openapi.json etc
Signed-off-by: Steve Taylor <[email protected]>

* add signature and signed-off-by
Signed-off-by: Steve Taylor <[email protected]>

* add signature and signed-off-by
Signed-off-by: Steve Taylor <[email protected]>

* escape < >
Signed-off-by: Steve Taylor <[email protected]>

* fix IMAGE_REPO var
Signed-off-by: Steve Taylor <[email protected]>

* run kubectl to get imagetags
Signed-off-by: Steve Taylor <[email protected]>

* pin pyyaml
Signed-off-by: Steve Taylor <[email protected]>

* remove namespace
Signed-off-by: Steve Taylor <[email protected]>

* remove namespace
Signed-off-by: Steve Taylor <[email protected]>

* remove namespace
Signed-off-by: Steve Taylor <[email protected]>

* remove namespace
Signed-off-by: Steve Taylor <[email protected]>

* remove namespace
Signed-off-by: Steve Taylor <[email protected]>

* Bump version: 9.3.235 → 9.3.236
Signed-off-by: Steve Taylor <[email protected]>

* remove namespace
Signed-off-by: Steve Taylor <[email protected]>

* remove pyyaml pin
Signed-off-by: Steve Taylor <[email protected]>

* Bump version: 9.3.236 → 9.3.237
Signed-off-by: Steve Taylor <[email protected]>

* handle comp parent correctly and no .git dir
Signed-off-by: Steve Taylor <[email protected]>

* Bump version: 9.3.237 → 9.3.238
Signed-off-by: Steve Taylor <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants