Skip to content

Update step-security/harden-runner action to v2.19.1#29

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/step-security-harden-runner-2.x
Open

Update step-security/harden-runner action to v2.19.1#29
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/step-security-harden-runner-2.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 30, 2024

This PR contains the following updates:

Package Type Update Change
step-security/harden-runner action minor v2.17.0v2.19.1

Release Notes

step-security/harden-runner (step-security/harden-runner)

v2.19.1

Compare Source

What's Changed

What the fix changes

  • Harden-Runner will detect ubuntu-slim runners and exit cleanly with an informational log message, instead of post harden runner step failing on chown: invalid user: 'undefined'.

What the fix does not do

  • Jobs running on ubuntu-slim will not be monitored by Harden-Runner. The agent relies on kernel-level features (that require elevated capabilities).
  • Per GitHub's docs on single-CPU runners: "The container for ubuntu-slim runners runs in unprivileged mode. This means that some operations requiring elevated privileges such as mounting file systems, using Docker-in-Docker, or accessing low-level kernel features are not supported." Those low-level kernel features are what the agent needs, so monitoring inside the unprivileged container is not feasible today.

For StepSecurity enterprise customers
If your security posture requires that workflows are always monitored, you can block the use of ubuntu-slim via workflow run policies see the Runner Label Policy docs. This lets you enforce that jobs only run on monitored runner types.

New Contributors

Full Changelog: step-security/harden-runner@v2.19.0...v2.19.1

v2.19.0

Compare Source

What's Changed
New Runner Support

Harden-Runner now supports Depot, Blacksmith, Namespace, and WarpBuild runners with the same egress monitoring, runtime monitoring, and policy enforcement available on GitHub-hosted runners.

Automated Incident Response for Supply Chain Attacks
  • Global block list: Outbound connections to known malicious domains and IPs are now blocked even in audit mode.
  • System-defined detection rules: Harden-Runner will trigger lockdown mode when a high risk event is detected during an active supply chain attack (for example, a process reading the memory of the runner worker process, a common technique for stealing GitHub Actions secrets).
Bug Fixes

Windows and macOS: stability and reliability fixes

Full Changelog: step-security/harden-runner@v2.18.0...v2.19.0

v2.18.0

Compare Source

What's Changed

Global Block List: During supply chain incidents like the recent axios and trivy compromises, StepSecurity will add known malicious domains and IP addresses (IOCs) to a global block list. These will be automatically blocked, even in audit mode, providing immediate protection without requiring any workflow changes.

Deploy on Self-Hosted VM: Added deploy-on-self-hosted-vm input that allows the Harden Runner agent to be installed directly on ephemeral self-hosted Linux runner VMs at workflow runtime. This is intended as an alternative when baking the agent into the VM image is not possible.

Full Changelog: step-security/harden-runner@v2.17.0...v2.18.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from d325d4e to ed65172 Compare May 22, 2024 01:08
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.7.1 Update step-security/harden-runner action to v2.8.0 May 22, 2024
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from ed65172 to c22da05 Compare June 9, 2024 05:15
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.8.0 Update step-security/harden-runner action to v2.8.1 Jun 9, 2024
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.8.1 Update step-security/harden-runner action to v2.9.0 Jul 21, 2024
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from c22da05 to f07bc12 Compare July 21, 2024 09:00
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from f07bc12 to ffc1b3e Compare August 6, 2024 00:42
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.9.0 Update step-security/harden-runner action to v2.9.1 Aug 6, 2024
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from ffc1b3e to cbf6c07 Compare September 11, 2024 00:33
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.9.1 Update step-security/harden-runner action to v2.10.0 Sep 11, 2024
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from cbf6c07 to 78e5311 Compare September 12, 2024 01:01
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.10.0 Update step-security/harden-runner action to v2.10.1 Sep 12, 2024
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.10.1 Update step-security/harden-runner action to v2.10.2 Nov 19, 2024
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from 78e5311 to 03e51d4 Compare November 19, 2024 00:56
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from 03e51d4 to 97986cb Compare January 11, 2025 12:07
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.10.2 Update step-security/harden-runner action to v2.10.3 Jan 11, 2025
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.10.3 Update step-security/harden-runner action to v2.10.4 Jan 20, 2025
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from 97986cb to 20b47fb Compare January 20, 2025 19:55
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.10.4 Update step-security/harden-runner action to v2.11.0 Feb 18, 2025
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from 20b47fb to 793c9dd Compare February 18, 2025 00:13
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.11.0 Update step-security/harden-runner action to v2.11.1 Apr 2, 2025
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from 793c9dd to 5f43c05 Compare April 2, 2025 00:13
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.11.1 Update step-security/harden-runner action to v2.12.0 Apr 22, 2025
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from 5f43c05 to 44d15a1 Compare April 22, 2025 00:27
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.12.0 Update step-security/harden-runner action to v2.12.1 Jun 12, 2025
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from 44d15a1 to c4da785 Compare June 12, 2025 00:55
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.12.1 Update step-security/harden-runner action to v2.12.2 Jul 1, 2025
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from c4da785 to 83558a8 Compare July 1, 2025 04:38
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.12.2 Update step-security/harden-runner action to v2.13.0 Jul 16, 2025
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from 83558a8 to 4f62e0e Compare July 16, 2025 00:49
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.13.1 Update step-security/harden-runner action to v2.13.2 Nov 8, 2025
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from 5f7377f to 90b2501 Compare November 8, 2025 08:03
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from 90b2501 to aab7219 Compare December 2, 2025 23:47
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.13.2 Update step-security/harden-runner action to v2.13.3 Dec 2, 2025
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from aab7219 to 827abac Compare December 10, 2025 07:29
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.13.3 Update step-security/harden-runner action to v2.14.0 Dec 10, 2025
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.14.0 Update step-security/harden-runner action to v2.14.1 Jan 27, 2026
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from 827abac to 8d54e87 Compare January 27, 2026 00:14
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from 8d54e87 to e0c2be3 Compare February 7, 2026 04:11
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.14.1 Update step-security/harden-runner action to v2.14.2 Feb 7, 2026
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.14.2 Update step-security/harden-runner action to v2.15.0 Mar 1, 2026
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from e0c2be3 to bbdb7a9 Compare March 1, 2026 23:09
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.15.0 Update step-security/harden-runner action to v2.15.1 Mar 7, 2026
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from bbdb7a9 to 427c817 Compare March 7, 2026 04:22
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from 427c817 to a4754ac Compare March 28, 2026 04:54
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.15.1 Update step-security/harden-runner action to v2.16.0 Mar 28, 2026
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.16.0 Update step-security/harden-runner action to v2.17.0 Apr 12, 2026
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from a4754ac to 90bfaf3 Compare April 12, 2026 14:38
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.17.0 Update step-security/harden-runner action to v2.17.0 - autoclosed Apr 12, 2026
@renovate renovate Bot closed this Apr 12, 2026
@renovate renovate Bot deleted the renovate/step-security-harden-runner-2.x branch April 12, 2026 14:51
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.17.0 - autoclosed Update step-security/harden-runner action to v2.18.0 Apr 15, 2026
@renovate renovate Bot reopened this Apr 15, 2026
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch 2 times, most recently from 90bfaf3 to f23bc07 Compare April 15, 2026 15:09
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.18.0 Update step-security/harden-runner action to v2.19.0 Apr 30, 2026
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from f23bc07 to e12a126 Compare April 30, 2026 01:33
@renovate renovate Bot changed the title Update step-security/harden-runner action to v2.19.0 Update step-security/harden-runner action to v2.19.1 May 3, 2026
@renovate renovate Bot force-pushed the renovate/step-security-harden-runner-2.x branch from e12a126 to 84e94dd Compare May 3, 2026 07:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants