Skip to content

Chore: Bump step-security/harden-runner from 2.13.2 to 2.13.3#24

Closed
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/github_actions/step-security/harden-runner-2.13.3
Closed

Chore: Bump step-security/harden-runner from 2.13.2 to 2.13.3#24
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/github_actions/step-security/harden-runner-2.13.3

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 8, 2025

Bumps step-security/harden-runner from 2.13.2 to 2.13.3.

Release notes

Sourced from step-security/harden-runner's releases.

v2.13.3

What's Changed

  • Fixed an issue where process events were not uploaded in certain edge cases.

Full Changelog: step-security/harden-runner@v2.13.2...v2.13.3

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Dec 8, 2025
@github-actions
Copy link

github-actions bot commented Dec 8, 2025

PR: #24
Mode: squash
Topic: GH-it-dep-24
Change-Ids:
I3d09e92a8bf3eec87c1929be6196274428777dfd
GitHub-Hash: 0b246d0fcaea1d10

@github-actions
Copy link

github-actions bot commented Dec 8, 2025

Change raised in Gerrit by GitHub2Gerrit: https://gerrit.o-ran-sc.org/r/c/it/dep/+/15339

oran-osc-github pushed a commit that referenced this pull request Dec 10, 2025
Bumps step-security/harden-runner from 2.13.2 to 2.13.3.
## Release notes

Sourced from step-security/harden-runner's releases.

v2.13.3
What's Changed

Fixed an issue where process events were not uploaded in certain edge cases.

Full Changelog: step-security/harden-runner@v2.13.2...v2.13.3

## Commits

df199fb Merge pull request #620 from step-security/rc-29
03d096a update agent
4090107 fix: update agent
See full diff in compare view

![Dependabot compatibility score](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Issue-ID: CIMAN-33
Signed-off-by: dependabot[bot] <[email protected]>
Signed-off-by: oran.gh2gerrit <[email protected]>
Change-Id: I47ae9a8fde850c6570ebed565b3508dd05419a65
GitHub-PR: #24
GitHub-Hash: 0b246d0fcaea1d10
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.13.2 to 2.13.3.
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](step-security/harden-runner@95d9a5d...df199fb)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-version: 2.13.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/github_actions/step-security/harden-runner-2.13.3 branch from 5c62895 to 7ace36a Compare December 10, 2025 17:39
@github-actions
Copy link

Change raised in Gerrit by GitHub2Gerrit: https://gerrit.o-ran-sc.org/r/c/it/dep/+/15355

1 similar comment
@github-actions
Copy link

Change raised in Gerrit by GitHub2Gerrit: https://gerrit.o-ran-sc.org/r/c/it/dep/+/15355

@github-actions
Copy link

Change raised in Gerrit by GitHub2Gerrit: https://gerrit.o-ran-sc.org/r/c/it/dep/+/15356

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Dec 15, 2025

Superseded by #25.

@dependabot dependabot bot closed this Dec 15, 2025
@dependabot dependabot bot deleted the dependabot/github_actions/step-security/harden-runner-2.13.3 branch December 15, 2025 20:26
oran-osc-github pushed a commit that referenced this pull request Feb 12, 2026
… 0.2.0

Bumps lfreleng-actions/repository-metadata-action from 0.1.2 to 0.2.0.
## Release notes

Sourced from lfreleng-actions/repository-metadata-action's releases.

v0.2.0
Breaking Change

Refactor!: Convert to Python, capture Gerrit environment parameters @​ModeSevenIndustrialSolutions (#20)

Maintenance

Chore: Bump actions/checkout from 5.0.1 to 6.0.0 @dependabot[bot] (#15)
Chore: Bump lfreleng-actions/draft-release-promote-action @dependabot[bot] (#16)
Chore: Fix tables in markdown documents @​ModeSevenIndustrialSolutions (#17)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#18)
Chore: Bump actions/checkout from 6.0.0 to 6.0.1 @dependabot[bot] (#24)
Chore: Bump step-security/harden-runner from 2.13.2 to 2.13.3 @dependabot[bot] (#23)
Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-verify-github-actions.yaml @dependabot[bot] (#22)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#21)
Chore: Bump step-security/harden-runner from 2.13.3 to 2.14.0 @dependabot[bot] (#26)
Chore: Bump actions/cache from 4.3.0 to 5.0.1 @dependabot[bot] (#28)
Chore: Bump actions/upload-artifact from 5.0.0 to 6.0.0 @dependabot[bot] (#27)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#29)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#30)
Chore: Update repository linting setup @​ModeSevenIndustrialSolutions (#31)
Refactor!: Convert to Python, capture Gerrit environment parameters @​ModeSevenIndustrialSolutions (#20)

Links

Submit bugs/feature requests

## Commits

ceabcd9 Merge pull request #20 from modeseven-lfreleng-actions/gerrit-metadata
f741239 Refactor!: Convert to Python, capture Gerrit environment parameters
9354e39 Merge pull request #31 from modeseven-lfreleng-actions/update-linting
e05b33e Chore: Update repository linting setup
b31c482 Merge pull request #30 from lfreleng-actions/pre-commit-ci-update-config
a6d41ba Chore: pre-commit autoupdate
5dd8b10 Merge pull request #29 from lfreleng-actions/pre-commit-ci-update-config
477b08a Chore: pre-commit autoupdate
e0c6f10 Merge pull request #27 from lfreleng-actions/dependabot/github_actions/action
7abc303 Merge pull request #28 from lfreleng-actions/dependabot/github_actions/action
Additional commits viewable in compare view

![Dependabot compatibility score](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

You can trigger a rebase of this PR by commenting `@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

Change-Id: I600a319096e483f8b2ce1d0fe389b1b814399daf

---

## Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show  ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

> **Note**
> Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Issue-ID: CIMAN-33
Signed-off-by: dependabot[bot] <[email protected]>
Change-Id: I265e7e988fd5b72092ad031817b7a8f0b7510bc3
GitHub-PR: #29
GitHub-Hash: b9ffd13fe50a92fd
Signed-off-by: oran.gh2gerrit <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Development

Successfully merging this pull request may close these issues.

0 participants