From be94606b7c6f525363ff848e07f169706e8c6bbb Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 29 Apr 2026 23:42:43 +0000 Subject: [PATCH] Bump step-security/harden-runner from 1.5.0 to 2.19.0 Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 1.5.0 to 2.19.0. - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](https://github.com/step-security/harden-runner/compare/2e205a28d0e1da00c5f53b161f4067b052c61f34...8d3c67de8e2fe68ef647c8db1e6a09f647780f40) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.19.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- .github/workflows/assign-to-project.yml | 2 +- .github/workflows/auto-assign-pr.yml | 2 +- .github/workflows/ci-build.yml | 2 +- .github/workflows/codeql-scan.yml | 2 +- .github/workflows/docker-linter.yml | 2 +- .github/workflows/mark-stale.yml | 2 +- .github/workflows/pr-labeler.yml | 2 +- .github/workflows/release-build.yml | 4 ++-- 8 files changed, 9 insertions(+), 9 deletions(-) diff --git a/.github/workflows/assign-to-project.yml b/.github/workflows/assign-to-project.yml index 1b7a4bc..6a4c84b 100644 --- a/.github/workflows/assign-to-project.yml +++ b/.github/workflows/assign-to-project.yml @@ -20,7 +20,7 @@ jobs: steps: - name: Harden Runner - uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 + uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 with: egress-policy: block allowed-endpoints: > diff --git a/.github/workflows/auto-assign-pr.yml b/.github/workflows/auto-assign-pr.yml index 2523408..5758eff 100644 --- a/.github/workflows/auto-assign-pr.yml +++ b/.github/workflows/auto-assign-pr.yml @@ -13,7 +13,7 @@ jobs: steps: - name: Harden Runner - uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 + uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 with: egress-policy: block allowed-endpoints: > diff --git a/.github/workflows/ci-build.yml b/.github/workflows/ci-build.yml index c0c3645..9c9043f 100644 --- a/.github/workflows/ci-build.yml +++ b/.github/workflows/ci-build.yml @@ -21,7 +21,7 @@ jobs: steps: - name: Harden Runner - uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 + uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 with: egress-policy: block allowed-endpoints: > diff --git a/.github/workflows/codeql-scan.yml b/.github/workflows/codeql-scan.yml index 2c74092..d9284f9 100644 --- a/.github/workflows/codeql-scan.yml +++ b/.github/workflows/codeql-scan.yml @@ -37,7 +37,7 @@ jobs: steps: - name: Harden Runner - uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 + uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 with: egress-policy: block allowed-endpoints: > diff --git a/.github/workflows/docker-linter.yml b/.github/workflows/docker-linter.yml index 5e93028..780df6f 100644 --- a/.github/workflows/docker-linter.yml +++ b/.github/workflows/docker-linter.yml @@ -29,7 +29,7 @@ jobs: steps: - name: Harden Runner - uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 + uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 with: egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs diff --git a/.github/workflows/mark-stale.yml b/.github/workflows/mark-stale.yml index 9220cad..49301c1 100644 --- a/.github/workflows/mark-stale.yml +++ b/.github/workflows/mark-stale.yml @@ -17,7 +17,7 @@ jobs: steps: - name: Harden Runner - uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 + uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 with: egress-policy: block allowed-endpoints: > diff --git a/.github/workflows/pr-labeler.yml b/.github/workflows/pr-labeler.yml index 8f04231..d555edd 100644 --- a/.github/workflows/pr-labeler.yml +++ b/.github/workflows/pr-labeler.yml @@ -19,7 +19,7 @@ jobs: steps: - name: Harden Runner - uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 + uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 with: egress-policy: block allowed-endpoints: > diff --git a/.github/workflows/release-build.yml b/.github/workflows/release-build.yml index a741b8c..533c88c 100644 --- a/.github/workflows/release-build.yml +++ b/.github/workflows/release-build.yml @@ -21,7 +21,7 @@ jobs: steps: - name: Harden Runner - uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 + uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 with: egress-policy: block allowed-endpoints: > @@ -62,7 +62,7 @@ jobs: steps: - name: Harden Runner - uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 + uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 with: egress-policy: block allowed-endpoints: >