Skip to content

Bump harden-runner to v2.20.1 for Node 24 runtime - #98

Open
justaugustus wants to merge 1 commit into
uwu-tools:mainfrom
justaugustus:chore/bump-harden-runner-node24
Open

Bump harden-runner to v2.20.1 for Node 24 runtime#98
justaugustus wants to merge 1 commit into
uwu-tools:mainfrom
justaugustus:chore/bump-harden-runner-node24

Conversation

@justaugustus

Copy link
Copy Markdown
Member

What

Bump step-security/harden-runner from v2.15.0 → v2.20.1 (SHA-pinned) in the Production sync and GitHub sync tests workflows.

Why

v2.15.0 declares using: node20, so GitHub now force-runs it on Node 24 and emits a deprecation warning on every job:

Node.js 20 is deprecated. The following actions target Node.js 20 but are being
forced to run on Node.js 24: step-security/harden-runner@a90bcbc... v2.15.0

v2.20.1 ships a node24 runtime (verified in its action.yml), which clears the warning. Pin: b09bb98e06d4d774595224525879c09bc6e98c40 = v2.20.1.

Notes

step-security/harden-runner v2.15.0 declares `using: node20`, so GitHub
now force-runs it on Node 24 and emits a deprecation warning on every
job:

  Node.js 20 is deprecated. The following actions target Node.js 20 but
  are being forced to run on Node.js 24: step-security/harden-runner@...

v2.20.1 ships a Node 24 runtime, which clears the warning. Update the
SHA-pinned reference in the Production sync and GitHub sync tests
workflows.

Assisted-by: Claude Code:claude-opus-4-8
Signed-off-by: Stephen Augustus <[email protected]>
@kusari-inspector

Copy link
Copy Markdown

⚠️ Workspace Mapping Required

Hello! We noticed that your GitHub organization is not yet mapped to a Kusari workspace. Kusari Inspector now requires installations to be associated with a Kusari workspace.

⚠️ NOTE: Only the admin who installed the Kusari GitHub App can complete these steps. If the admin is unable to complete these steps, please contact [email protected]

To complete the setup:

  1. Visit https://console.us.kusari.cloud/auth/github and log in via github
  2. If you have only one workspace, it will be automatically selected for you
  3. Once the mapping is complete, return here and create a new comment with: @kusari-inspector re-run

This will trigger the analysis to run again.

For more information, or if you need help, visit https://github.com/kusaridev/community/discussions

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant