chore(deps): update non-major github actions - #23
Open
renovate-coveooss[bot] wants to merge 1 commit into
Open
Conversation
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
June 18, 2025 14:34
c1913cc to
fae52df
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
July 7, 2025 06:34
fae52df to
c73a671
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
July 22, 2025 19:37
c73a671 to
ac9f808
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
August 18, 2025 10:33
ac9f808 to
2b5b714
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
August 27, 2025 11:37
2b5b714 to
abf1611
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
September 16, 2025 18:03
abf1611 to
d6c6609
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
October 15, 2025 21:34
d6c6609 to
02e0d48
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
November 12, 2025 08:03
02e0d48 to
40e3168
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
November 20, 2025 23:33
40e3168 to
b870b1a
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
December 9, 2025 05:03
b870b1a to
491708a
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
2 times, most recently
from
December 22, 2025 18:31
c4e4f46 to
8011862
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
February 2, 2026 05:01
8011862 to
5723471
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
2 times, most recently
from
February 18, 2026 02:06
feed6cb to
6902822
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
March 3, 2026 23:40
6902822 to
c684e16
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
March 12, 2026 21:12
c684e16 to
cac664d
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
March 23, 2026 07:32
cac664d to
c9fd791
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
April 6, 2026 19:02
c9fd791 to
76e36cd
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
2 times, most recently
from
April 22, 2026 08:01
734226d to
dacb21d
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
April 27, 2026 08:02
dacb21d to
7157424
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
May 11, 2026 00:05
7157424 to
319aba3
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
May 20, 2026 20:33
319aba3 to
edbfce4
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
2 times, most recently
from
May 28, 2026 16:35
a7efe6e to
061eef3
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
July 14, 2026 10:02
061eef3 to
a944b99
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
July 27, 2026 16:03
a944b99 to
6a380df
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
August 12, 2026 08:06
6a380df to
abb49ef
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
August 24, 2026 05:04
abb49ef to
ae37c06
Compare
renovate-coveooss
Bot
force-pushed
the
renovate/github-actions-non-major
branch
from
August 27, 2026 08:05
ae37c06 to
93322cd
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v4.2.2→v4.4.0v5.4.0→v5.6.01.21→1.27v2.11.1→v2.21.0v2.21.1[skip release]
Release Notes
actions/checkout (actions/checkout)
v4.4.0Compare Source
What's Changed
allow-unsafe-pr-checkoutto v4 by @aiqiaoy in #2502https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change
Full Changelog: actions/checkout@v4.3.1...v4.4.0
v4.3.1Compare Source
v4.3.0Compare Source
actions/setup-go (actions/setup-go)
v5.6.0Compare Source
What's Changed
Full Changelog: actions/setup-go@v5...v5.6.0
v5.5.0Compare Source
What's Changed
Bug fixes:
Dependency updates:
New Contributors
Full Changelog: actions/setup-go@v5...v5.5.0
actions/go-versions (go)
v1.27.0: 1.27.0Compare Source
Go 1.27.0
v1.26.7: 1.26.7Compare Source
Go 1.26.7
v1.26.6: 1.26.6Compare Source
Go 1.26.6
v1.26.5: 1.26.5Compare Source
Go 1.26.5
v1.26.4: 1.26.4Compare Source
Go 1.26.4
v1.26.3: 1.26.3Compare Source
Go 1.26.3
v1.26.2: 1.26.2Compare Source
Go 1.26.2
v1.26.1: 1.26.1Compare Source
Go 1.26.1
v1.26.0: 1.26.0Compare Source
Go 1.26.0
v1.25.14: 1.25.14Compare Source
Go 1.25.14
v1.25.13: 1.25.13Compare Source
Go 1.25.13
v1.25.12: 1.25.12Compare Source
Go 1.25.12
v1.25.11: 1.25.11Compare Source
Go 1.25.11
v1.25.10: 1.25.10Compare Source
Go 1.25.10
v1.25.9: 1.25.9Compare Source
Go 1.25.9
v1.25.8: 1.25.8Compare Source
Go 1.25.8
v1.25.7: 1.25.7Compare Source
Go 1.25.7
v1.25.6: 1.25.6Compare Source
Go 1.25.6
v1.25.5: 1.25.5Compare Source
Go 1.25.5
v1.25.4: 1.25.4Compare Source
Go 1.25.4
v1.25.3: 1.25.3Compare Source
Go 1.25.3
v1.25.2: 1.25.2Compare Source
Go 1.25.2
v1.25.1: 1.25.1Compare Source
Go 1.25.1
v1.25.0: 1.25.0Compare Source
Go 1.25.0
v1.24.13: 1.24.13Compare Source
Go 1.24.13
v1.24.12: 1.24.12Compare Source
Go 1.24.12
v1.24.11: 1.24.11Compare Source
Go 1.24.11
v1.24.10: 1.24.10Compare Source
Go 1.24.10
v1.24.9: 1.24.9Compare Source
Go 1.24.9
v1.24.8: 1.24.8Compare Source
Go 1.24.8
v1.24.7: 1.24.7Compare Source
Go 1.24.7
v1.24.6: 1.24.6Compare Source
Go 1.24.6
v1.24.5: 1.24.5Compare Source
Go 1.24.5
v1.24.4: 1.24.4Compare Source
Go 1.24.4
v1.24.3: 1.24.3Compare Source
Go 1.24.3
v1.24.2: 1.24.2Compare Source
Go 1.24.2
v1.24.1: 1.24.1Compare Source
Go 1.24.1
v1.24.0: 1.24.0Compare Source
Go 1.24.0
v1.23.12: 1.23.12Compare Source
Go 1.23.12
v1.23.11: 1.23.11Compare Source
Go 1.23.11
v1.23.10: 1.23.10Compare Source
Go 1.23.10
v1.23.9: 1.23.9Compare Source
Go 1.23.9
v1.23.8: 1.23.8Compare Source
Go 1.23.8
v1.23.7: 1.23.7Compare Source
Go 1.23.7
v1.23.6: 1.23.6Compare Source
Go 1.23.6
v1.23.5: 1.23.5Compare Source
Go 1.23.5
v1.23.4: 1.23.4Compare Source
Go 1.23.4
v1.23.3: 1.23.3Compare Source
Go 1.23.3
v1.23.2: 1.23.2Compare Source
Go 1.23.2
v1.23.1: 1.23.1Compare Source
Go 1.23.1
v1.23.0: 1.23.0Compare Source
Go 1.23.0
v1.22.12: 1.22.12Compare Source
Go 1.22.12
v1.22.11: 1.22.11Compare Source
Go 1.22.11
v1.22.10: 1.22.10Compare Source
Go 1.22.10
v1.22.9: 1.22.9Compare Source
Go 1.22.9
v1.22.8: 1.22.8Compare Source
Go 1.22.8
v1.22.7: 1.22.7Compare Source
Go 1.22.7
v1.22.6: 1.22.6Compare Source
Go 1.22.6
v1.22.5: 1.22.5Compare Source
Go 1.22.5
v1.22.4: 1.22.4Compare Source
Go 1.22.4
v1.22.3: 1.22.3Compare Source
Go 1.22.3
v1.22.2: 1.22.2Compare Source
Go 1.22.2
v1.22.1: 1.22.1Compare Source
Go 1.22.1
v1.22.0: 1.22.0Compare Source
Go 1.22.0
step-security/harden-runner (step-security/harden-runner)
v2.21.0Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2.20.1...v2.21.0
v2.20.1Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2.20.0...v2.20.1
v2.20.0Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2.19.4...v2.20.0
v2.19.4Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2.19.3...v2.19.4
v2.19.3Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2.19.2...v2.19.3
v2.19.2Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2.19.1...v2.19.2
v2.19.1Compare Source
What's Changed
What the fix changes
ubuntu-slimrunners and exit cleanly with an informational log message, instead of post harden runner step failing on chown: invalid user: 'undefined'.What the fix does not do
ubuntu-slimwill not be monitored by Harden-Runner. The agent relies on kernel-level features (that require elevated capabilities).For StepSecurity enterprise customers
If your security posture requires that workflows are always monitored, you can block the use of
ubuntu-slimvia workflow run policies see the Runner Label Policy docs. This lets you enforce that jobs only run on monitored runner types.New Contributors
Full Changelog: step-security/harden-runner@v2.19.0...v2.19.1
v2.19.0Compare Source
What's Changed
New Runner Support
Harden-Runner now supports Depot, Blacksmith, Namespace, and WarpBuild runners with the same egress monitoring, runtime monitoring, and policy enforcement available on GitHub-hosted runners.
Automated Incident Response for Supply Chain Attacks
Bug Fixes
Windows and macOS: stability and reliability fixes
Full Changelog: step-security/harden-runner@v2.18.0...v2.19.0
v2.18.0Compare Source
What's Changed
Global Block List: During supply chain incidents like the recent axios and trivy compromises, StepSecurity will add known malicious domains and IP addresses (IOCs) to a global block list. These will be automatically blocked, even in audit mode, providing immediate protection without requiring any workflow changes.
Deploy on Self-Hosted VM: Added
deploy-on-self-hosted-vminput that allows the Harden Runner agent to be installed directly on ephemeral self-hosted Linux runner VMs at workflow runtime. This is intended as an alternative when baking the agent into the VM image is not possible.Full Changelog: step-security/harden-runner@v2.17.0...v2.18.0
v2.17.0Compare Source
What's Changed
Policy Store Support
Added
use-policy-storeandapi-keyinputs to fetch security policies directly from the StepSecurity Policy Store. Policies can be defined and attached at the workflow, repo, org, or cluster (ARC) level, with the most granular policy taking precedence. This is the preferred method over the existingpolicyinput which requiresid-token: writepermission. If no policy is found in the store, the action defaults to audit mode.Full Changelog: step-security/harden-runner@v2.16.1...v2.17.0
v2.16.1Compare Source
What's Changed
Enterprise tier: Added support for direct IP addresses in the allow list
Community tier: Migrated Harden Runner telemetry to a new endpoint
Full Changelog: step-security/harden-runner@v2.16.0...v2.16.1
v2.16.0Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2.15.1...v2.16.0
v2.15.1Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2.15.0...v2.15.1
v2.15.0Compare Source
What's Changed
Windows and macOS runner support
We are excited to announce that Harden Runner now supports Windows and macOS runners, extending runtime security beyond Linux for the first time.
Insights for Windows and macOS runners will be displayed in the same consistent format you are already familiar with from Linux runners, giving you a unified view of runtime activity across all platforms.
Full Changelog: step-security/harden-runner@v2.14.2...v2.15.0
v2.14.2Compare Source
What's Changed
Security fix: Fixed a medium severity vulnerability where outbound network connections using sendto, sendmsg, and sendmmsg socket system calls could bypass audit logging when using egress-policy: audit. This issue only affects the Community Tier in audit mode; block mode and Enterprise Tier were not affected. See GHSA-cpmj-h4f6-r6pq for details.
Full Changelog: step-security/harden-runner@v2.14.1...v2.14.2
v2.14.1Compare Source
What's Changed
In some self-hosted environments, the agent could briefly fall back to public DNS resolvers during startup if the system DNS was not yet available. This behavior was unintended for GitHub-hosted runners and has now been fixed to prevent any use of public DNS resolvers.
Fixed npm audit vulnerabilities
Full Changelog: step-security/harden-runner@v2.14.0...v2.14.1
v2.14.0Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2.13.3...v2.14.0
v2.13.3Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2.13.2...v2.13.3
v2.13.2Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2.13.1...v2.13.2
v2.13.1Compare Source
What's Changed
Graceful handling of HTTP errors: Improved error handling when fetching Harden Runner policies from the StepSecurity Policy Store API, ensuring more reliable execution even in case of temporary network/API issues.
Security updates for npm dependencies: Updated vulnerable npm package dependencies to the latest secure versions.
Faster enterprise agent downloads: The enterprise agent is now downloaded from GitHub Releases instead of packages.stepsecurity.io, improving download speed and reliability.
Full Changelog: step-security/harden-runner@v2.13.0...v2.13.1
v2.13.0Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2...v2.13.0
v2.12.2Compare Source
What's Changed
Added HTTPS Monitoring for additional destinations - *.githubusercontent.com
Bug fixes:
Full Changelog: step-security/harden-runner@v2...v2.12.2
v2.12.1Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2...v2.12.1
v2.12.0Compare Source
What's Changed
A new option,
disable-sudo-and-containers, is now available to replace thedisable-sudo policy, addressing Docker-based privilege escalation (CVE-2025-32955). More details can be found in this blog post.New detections have been added based on insights from the tj-actions and reviewdog actions incidents.
Full Changelog: step-security/harden-runner@v2...v2.12.0
Configuration
📅 Schedule: (in timezone America/Toronto)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.