Bump step-security/harden-runner from 1.5.0 to 2.10.1
Bumps step-security/harden-runner from 1.5.0 to 2.10.1.
Release notes
Sourced from step-security/harden-runner's releases.
v2.10.1
What's Changed
Release v2.10.1 by
@varunsh-coderin step-security/harden-runner#463 Bug fix: Resolves an issue where DNS resolution of .local domains was failing when using a Kind cluster in a GitHub Actions workflow.Full Changelog: https://github.com/step-security/harden-runner/compare/v2...v2.10.1
v2.10.0
What's Changed
Release v2.10.0 by
@h0x0erand@varunsh-coderin step-security/harden-runner#455ARM Support: Harden-Runner Enterprise tier now supports GitHub-hosted ARM runners. This includes all the features that apply to previously supported GitHub-hosted x64 Linux runners.
Full Changelog: https://github.com/step-security/harden-runner/compare/v2...v2.10.0
v2.9.1
What's Changed
Release v2.9.1 by
@h0x0erand@varunsh-coderin #440 This release includes two changes:
- Updated markdown displayed in the job summary by the Harden-Runner Action.
- Fixed a bug affecting Enterprise Tier customers where the agent attempted to upload telemetry for jobs with disable-telemetry set to true. No telemetry was uploaded as the endpoint was not in the allowed list.
Full Changelog: https://github.com/step-security/harden-runner/compare/v2...v2.9.1
v2.9.0
What's Changed
Release v2.9.0 by
@h0x0erand@varunsh-coderin step-security/harden-runner#435 This release includes:
- Enterprise Tier - Telemetry Upload Enhancement: For the enterprise tier, this change helps overcome size constraints, allowing for more reliable telemetry uploads from the Harden-Runner agent to the StepSecurity backend API. No configuration change is needed to enable this.
- Harden-Runner Agent Authentication: The Harden-Runner agent now uses a per-job key to authenticate to the StepSecurity backend API to submit telemetry. This change prevents the submission of telemetry data anonymously for a given job, improving the integrity of the data collection process. No configuration change is needed to enable this.
- README Update: A Table of Contents has been added to the README file to improve navigation. This makes it easier for users to find the information they need quickly.
- Dependency Update: Updated the
bracesnpm package dependency to a non-vulnerable version. The vulnerability inbracesdid not affect the Harden Runner ActionFull Changelog: https://github.com/step-security/harden-runner/compare/v2...v2.9.0
v2.8.1
What's Changed
- Bug fix: Update isGitHubHosted implementation by
@varunsh-coderin step-security/harden-runner#425 The previous implementation incorrectly identified large GitHub-hosted runners as self-hosted runners. As a result, harden-runner was not executing on these large GitHub-hosted runners.Full Changelog: https://github.com/step-security/harden-runner/compare/v2...v2.8.1
v2.8.0
What's Changed
Release v2.8.0 by
@h0x0erand@varunsh-coderin step-security/harden-runner#416 This release includes:
... (truncated)
Commits
91182ccMerge pull request #463 from step-security/rc-1459ec1c6Update agent1d23703Merge pull request #461 from step-security/varunsh-coder-patch-1b03bddaUpdate README.md3d8dd68Update README.md446798fMerge pull request #455 from step-security/rc-12f0d3b1eUpdate agentb7880a2update distdade49eMerge pull request #456 from h0x0er/arm-supportd6248bebump enterprise agent version- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)