build(deps): Bump step-security/harden-runner from 2.14.0 to 2.16.1#4141
build(deps): Bump step-security/harden-runner from 2.14.0 to 2.16.1#4141dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.14.0 to 2.16.1. - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@20cf305...fe10465) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.16.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
PR: #4141 Note: This metadata is also included in the Gerrit commit message for reconciliation. |
|
Change raised in Gerrit by GitHub2Gerrit: https://gerrit.fd.io/r/c/csit/+/45416 |
|
Auto-closing pull request |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps step-security/harden-runner from 2.14.0 to 2.16.1. ## Release notes Sourced from step-security/harden-runner's releases. v2.16.1 What's Changed Enterprise tier: Added support for direct IP addresses in the allow list Community tier: Migrated Harden Runner telemetry to a new endpoint Full Changelog: step-security/harden-runner@v2.16.0...v2.16.1 v2.16.0 What's Changed Updated action.yml to use node24 Security fix: Fixed a medium severity vulnerability where the egress block policy could be bypassed via DNS over HTTPS (DoH) by proxying DNS queries through a permitted resolver, allowing data exfiltration even with a restrictive allowed-endpoints list. This issue only affects the Community Tier; the Enterprise Tier is not affected. See GHSA-46g3-37rh-v698 for details. Security fix: Fixed a medium severity vulnerability where the egress block policy could be bypassed via DNS queries over TCP to external resolvers, allowing outbound network communication that evades configured network restrictions. This issue only affects the Community Tier; the Enterprise Tier is not affected. See GHSA-g699-3x6g-wm3g for details. Full Changelog: step-security/harden-runner@v2.15.1...v2.16.0 v2.15.1 What's Changed Fixes step-security/harden-runner#642 bug due to which post step was failing on Windows ARM runners Updates npm packages Full Changelog: step-security/harden-runner@v2.15.0...v2.15.1 v2.15.0 What's Changed Windows and macOS runner support We are excited to announce that Harden Runner now supports Windows and macOS runners, extending runtime security beyond Linux for the first time. Insights for Windows and macOS runners will be displayed in the same consistent format you are already familiar with from Linux runners, giving you a unified view of runtime activity across all platforms. Full Changelog: step-security/harden-runner@v2.14.2...v2.15.0 v2.14.2 What's Changed Security fix: Fixed a medium severity vulnerability where outbound network connections using sendto, sendmsg, and sendmmsg socket system calls could bypass audit logging when using egress-policy: audit. This issue only affects the Community Tier in audit mode; block mode and Enterprise Tier were not affected. See GHSA-cpmj-h4f6-r6pq for details. Full Changelog: step-security/harden-runner@v2.14.1...v2.14.2 v2.14.1 What's Changed In some self-hosted environments, the agent could briefly fall back to public DNS resolvers during startup if the system DNS was not yet available. This behavior was unintended for GitHub-hosted runners and has now been fixed to prevent any use of public DNS resolvers. Fixed npm audit vulnerabilities Full Changelog: step-security/harden-runner@v2.14.0...v2.14.1 ## Commits fe10465 v2.16.1 (#654) fa2e9d6 Release v2.16.0 (#646) 58077d3 Release v2.15.1 (#641) a90bcbc Update readme (#637) f0a59d8 Release v2.15.0 (#639) 5ef0c07 Merge pull request #635 from step-security/rc-34 eb43c7b update agent e3f713f Merge pull request #631 from step-security/rc-31 423acdd chore: fix npm audit vulnerabilities 0ddb86c update agent See full diff in compare view  Signed-off-by: dependabot[bot] <support@github.com> Change-Id: Ie3c68f9f87cf24c9fe0d2aff98e6be133265699e GitHub-PR: #4141 GitHub-Hash: 029f605f67e7603e Signed-off-by: fdio.github <releng+fdio-github@linuxfoundation.org>
Bumps step-security/harden-runner from 2.14.0 to 2.16.1.
Release notes
Sourced from step-security/harden-runner's releases.
Commits
fe10465v2.16.1 (#654)fa2e9d6Release v2.16.0 (#646)58077d3Release v2.15.1 (#641)a90bcbcUpdate readme (#637)f0a59d8Release v2.15.0 (#639)5ef0c07Merge pull request #635 from step-security/rc-34eb43c7bupdate agente3f713fMerge pull request #631 from step-security/rc-31423acddchore: fix npm audit vulnerabilities0ddb86cupdate agentDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)