Skip to content

Update github actions (main) (minor)#227

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/main-github-actions
Open

Update github actions (main) (minor)#227
renovate[bot] wants to merge 1 commit intomainfrom
renovate/main-github-actions

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Dec 10, 2025

This PR contains the following updates:

Package Type Update Change
github/codeql-action action minor v4.31.11v4.32.3
step-security/harden-runner action minor v2.13.3v2.14.2

Release Notes

github/codeql-action (github/codeql-action)

v4.32.3

Compare Source

  • Added experimental support for testing connections to private package registries. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for Default Setup. #​3466

v4.32.2

Compare Source

v4.32.1

Compare Source

  • A warning is now shown in Default Setup workflow logs if a private package registry is configured using a GitHub Personal Access Token (PAT), but no username is configured. #​3422
  • Fixed a bug which caused the CodeQL Action to fail when repository properties cannot successfully be retrieved. #​3421

v4.32.0

Compare Source

step-security/harden-runner (step-security/harden-runner)

v2.14.2

Compare Source

What's Changed

Security fix: Fixed a medium severity vulnerability where outbound network connections using sendto, sendmsg, and sendmmsg socket system calls could bypass audit logging when using egress-policy: audit. This issue only affects the Community Tier in audit mode; block mode and Enterprise Tier were not affected. See GHSA-cpmj-h4f6-r6pq for details.

Full Changelog: step-security/harden-runner@v2.14.1...v2.14.2

v2.14.1

Compare Source

What's Changed

  1. In some self-hosted environments, the agent could briefly fall back to public DNS resolvers during startup if the system DNS was not yet available. This behavior was unintended for GitHub-hosted runners and has now been fixed to prevent any use of public DNS resolvers.

  2. Fixed npm audit vulnerabilities

Full Changelog: step-security/harden-runner@v2.14.0...v2.14.1

v2.14.0

Compare Source

What's Changed
  • Selective installation: Harden-Runner now skips installation on GitHub-hosted runners when the repository has a custom property skip_harden_runner, allowing organizations to opt out specific repos.
  • Avoid double install: The action no longer installs Harden-Runner if it’s already present on a GitHub-hosted runner, which could happen when a composite action also installs it.

Full Changelog: step-security/harden-runner@v2.13.3...v2.14.0


Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM ( * 0-3 * * * ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/main-github-actions branch from cbb45d8 to 5c7cff1 Compare December 15, 2025 18:11
@renovate renovate bot force-pushed the renovate/main-github-actions branch from 5c7cff1 to 6af89d1 Compare December 31, 2025 14:33
@renovate renovate bot changed the title Update step-security/harden-runner action to v2.14.0 (main) Update step-security/harden-runner action to v2.14.1 (main) Jan 26, 2026
@renovate renovate bot force-pushed the renovate/main-github-actions branch from 6af89d1 to b0d947a Compare January 26, 2026 05:50
@renovate renovate bot changed the title Update step-security/harden-runner action to v2.14.1 (main) Update github actions (main) (minor) Jan 26, 2026
@renovate renovate bot force-pushed the renovate/main-github-actions branch 2 times, most recently from 9855c35 to 4816c88 Compare February 2, 2026 17:15
@renovate renovate bot force-pushed the renovate/main-github-actions branch 2 times, most recently from 8bb112d to 21dfc1a Compare February 7, 2026 04:56
@renovate renovate bot force-pushed the renovate/main-github-actions branch from 21dfc1a to be50dc6 Compare February 13, 2026 12:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants