Repository navigation
Bump step-security/harden-runner from 2.20.0 to 2.21.1 - #36
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.20.0 to 2.21.1. - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@bf7454d...e14015d) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.21.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
|
PR: #36 Note: This metadata is also included in the Gerrit commit message for reconciliation. |
|
Change raised in Gerrit by GitHub2Gerrit: https://gerrit.onap.org/r/c/so/+/148043 |
## Release notes Sourced from step-security/harden-runner's releases. v2.21.1 What's Changed Improved performance of the disable-sudo feature. Fixed an issue in the Community tier where new endpoints required by the GitHub Actions runner were not being implicitly allowed in block mode. Fixed the Harden-Runner post step failing on Linux distributions that do not have a merged /usr filesystem layout (for example Debian 11), where /usr/bin/echo does not exist. This mainly affected self-hosted runners. Documentation updates: clarified which features are in the Community (free) vs Enterprise tier. Full Changelog: step-security/harden-runner@v2.21.0...v2.21.1 v2.21.0 What's Changed Support for denied endpoints in block mode. This is included in the enterprise tier. Customers can deny outbound calls, for example, to public package registries. Improved Support for AWS CodeBuild GitHub Actions Runners. Bug fixes. Full Changelog: step-security/harden-runner@v2.20.1...v2.21.0 v2.20.1 What's Changed AWS CodeBuild-hosted runner support Implicitly allow single-labeled (internal) domains in block-mode Full Changelog: step-security/harden-runner@v2.20.0...v2.20.1 ## Commits e14015d Merge pull request #690 from step-security/rc-43 9001249 docs: update harden-runner version pin to v2.21.0 in getting started example a447fba docs: expand enterprise feature list and document custom VM and ubuntu-slim l b0eaf8d docs: clarify community vs enterprise tiers and add maintained actions section 063e8e3 Merge pull request #687 from rohan-stepsecurity/rp/fix/bin-echo-fallback f46bdc1 chore: bump agent-ebpf to v1.9.1 and agent to v0.16.3 42e6daa fix: fall back to /bin/echo for non-usr-merged distros 05e3151 Merge pull request #684 from step-security/rc-42 0f37afa fix: ignore denied-endpoints on non-enterprise tier 93b58ee fix: resolve cache host read-first and never downgrade egress policy Additional commits viewable in compare view  Issue-ID: CIMAN-33 Signed-off-by: dependabot[bot] <[email protected]> Change-Id: Idaa9226d9430d4c2501b05cf39489ebb7a72a1b5 GitHub-PR: #36 GitHub-Hash: 606a8947e570ac6e Signed-off-by: onap.gh2gerrit <[email protected]>
|
Automated PR Closure This pull request has been automatically closed by GitHub2Gerrit. The corresponding Gerrit change has been accepted and merged ✅ The changes from this PR are now part of the main codebase in Gerrit. This is an automated action performed by the GitHub2Gerrit tool. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps step-security/harden-runner from 2.20.0 to 2.21.1.
Release notes
Sourced from step-security/harden-runner's releases.
Commits
e14015dMerge pull request #690 from step-security/rc-439001249docs: update harden-runner version pin to v2.21.0 in getting started examplea447fbadocs: expand enterprise feature list and document custom VM and ubuntu-slim l...b0eaf8ddocs: clarify community vs enterprise tiers and add maintained actions section063e8e3Merge pull request #687 from rohan-stepsecurity/rp/fix/bin-echo-fallbackf46bdc1chore: bump agent-ebpf to v1.9.1 and agent to v0.16.342e6daafix: fall back to/bin/echofor non-usr-merged distros05e3151Merge pull request #684 from step-security/rc-420f37afafix: ignore denied-endpoints on non-enterprise tier93b58eefix: resolve cache host read-first and never downgrade egress policyDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)