mirror of
https://github.com/konstruktoid/hardening.git
synced 2026-04-25 16:55:53 +03:00
[PR #726] [CLOSED] chore(deps): update step-security/harden-runner action to v2.14.2 - autoclosed #725
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/konstruktoid/hardening/pull/726
Author: @renovate[bot]
Created: 2/7/2026
Status: ❌ Closed
Base:
master← Head:renovate/step-security-harden-runner-2.x📝 Commits (1)
37dbccdchore(deps): update step-security/harden-runner action to v2.14.2📊 Changes
5 files changed (+5 additions, -5 deletions)
View changed files
📝
.github/workflows/dependency-review.yml(+1 -1)📝
.github/workflows/issues.yml(+1 -1)📝
.github/workflows/scorecards.yml(+1 -1)📝
.github/workflows/shellcheck.yml(+1 -1)📝
.github/workflows/slsa.yml(+1 -1)📄 Description
This PR contains the following updates:
v2.14.1→v2.14.2Release Notes
step-security/harden-runner (step-security/harden-runner)
v2.14.2Compare Source
What's Changed
Security fix: Fixed a medium severity vulnerability where outbound network connections using sendto, sendmsg, and sendmmsg socket system calls could bypass audit logging when using egress-policy: audit. This issue only affects the Community Tier in audit mode; block mode and Enterprise Tier were not affected. See GHSA-cpmj-h4f6-r6pq for details.
Full Changelog: https://github.com/step-security/harden-runner/compare/v2.14.1...v2.14.2
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.