Skip to content

Chore: Bump step-security/harden-runner from 2.12.1 to 2.13.0#7

Closed
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/github_actions/step-security/harden-runner-2.13.0
Closed

Chore: Bump step-security/harden-runner from 2.12.1 to 2.13.0#7
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/github_actions/step-security/harden-runner-2.13.0

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Aug 26, 2025

Bumps step-security/harden-runner from 2.12.1 to 2.13.0.

Release notes

Sourced from step-security/harden-runner's releases.

v2.13.0

What's Changed

  • Improved job markdown summary
  • Https monitoring for all domains (included with the enterprise tier)

Full Changelog: step-security/harden-runner@v2...v2.13.0

v2.12.2

What's Changed

Added HTTPS Monitoring for additional destinations - *.githubusercontent.com Bug fixes:

  • Implicitly allow local multicast, local unicast and broadcast IP addresses in block mode
  • Increased policy map size for block mode

Full Changelog: step-security/harden-runner@v2...v2.12.2

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.12.1 to 2.13.0.
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](step-security/harden-runner@002fdce...ec9f2d5)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-version: 2.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 26, 2025
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Sep 15, 2025

Superseded by #11.

@dependabot dependabot bot closed this Sep 15, 2025
@dependabot dependabot bot deleted the dependabot/github_actions/step-security/harden-runner-2.13.0 branch September 15, 2025 20:23
oran-osc-github pushed a commit that referenced this pull request Nov 6, 2025
[//]: # (dependabot-start)
⚠️ **Dependabot is rebasing this PR** ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Change-Id: Ie2c46935aa4f05f5f957a21ab8bb745eb8e502fc

---

[//]: # (dependabot-end)

Bumps lfreleng-actions/nexus-publish-action from 0.1.1 to 0.1.3.
## Release notes

Sourced from lfreleng-actions/nexus-publish-action's releases.

v0.1.3
Maintenance

Chore: Bump actions/download-artifact from 4.3.0 to 5.0.0 @dependabot[bot] (#12)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#13)
Chore: Bump lfreleng-actions/tag-push-verify-action from 0.1.0 to 0.1.1 @dependabot[bot] (#16)
Chore: Bump actions/checkout from 4.2.2 to 5.0.0 @dependabot[bot] (#15)
Chore: Bump amannn/action-semantic-pull-request from 5.5.3 to 6.0.1 @dependabot[bot] (#14)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#18)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#21)
Chore: Bump amannn/action-semantic-pull-request from 6.0.1 to 6.1.1 @dependabot[bot] (#20)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#22)
Chore: Bump azure/setup-helm from 4.3.0 to 4.3.1 @dependabot[bot] (#19)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#23)
Chore: Bump step-security/harden-runner from 2.13.0 to 2.13.1 @dependabot[bot] (#24)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#25)
Chore: Bump lfit/releng-reusable-workflows from 0.2.18 to 0.2.19 @dependabot[bot] (#27)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#28)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#29)
Chore: Bump lfit/releng-reusable-workflows from 0.2.19 to 0.2.21 @dependabot[bot] (#30)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#31)
Chore: Bump lfit/releng-reusable-workflows from 0.2.21 to 0.2.22 @dependabot[bot] (#32)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#33)
Chore: Bump actions/upload-artifact from 4.6.2 to 5.0.0 @dependabot[bot] (#37)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#35)
Chore: Bump lfit/releng-reusable-workflows from 0.2.22 to 0.2.24 @dependabot[bot] (#36)
Chore: Bump actions/download-artifact from 5.0.0 to 6.0.0 @dependabot[bot] (#38)

Code Quality

CI: Update tag-push.yaml workflow @​ModeSevenIndustrialSolutions (#17)
Test: Update helm repository, detect failures @​ModeSevenIndustrialSolutions (#26)

Links

Submit bugs/feature requests

v0.1.2
Bug Fixes

Fix: Refactor logging and address potential credential leakage @​ModeSevenIndustrialSolutions (#10)

Maintenance

Chore: pre-commit autoupdate @pre-commit-ci[bot] (#8)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#9)
Chore: Bump step-security/harden-runner from 2.12.2 to 2.13.0 @dependabot[bot] (#7)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#11)

Code Quality

... (truncated)

## Commits

b53a463 Merge pull request #38 from lfreleng-actions/dependabot/github_actions/action
c87c6f8 Merge pull request #36 from lfreleng-actions/dependabot/github_actions/lfit/r
76fad23 Merge pull request #35 from lfreleng-actions/pre-commit-ci-update-config
82d6e36 Merge pull request #37 from lfreleng-actions/dependabot/github_actions/action
09b1251 Chore: pre-commit autoupdate
026940a Chore: Bump actions/download-artifact from 5.0.0 to 6.0.0
a300fe2 Chore: Bump actions/upload-artifact from 4.6.2 to 5.0.0
c529fd4 Chore: Bump lfit/releng-reusable-workflows from 0.2.22 to 0.2.24
58b9c17 Merge pull request #33 from lfreleng-actions/pre-commit-ci-update-config
9215ef4 Merge pull request #32 from lfreleng-actions/dependabot/github_actions/lfit/r
Additional commits viewable in compare view

![Dependabot compatibility score](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Issue-ID: CIMAN-33
Signed-off-by: dependabot[bot] <[email protected]>
Signed-off-by: oran.gh2gerrit <[email protected]>
Change-Id: I2e5356e091f77667e075aeee03c42e5aa7cbab14
GitHub-PR: #14
GitHub-Hash: f67a059401e2016b
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Development

Successfully merging this pull request may close these issues.

0 participants