Open dependabot[bot] opened 3 days ago
This PR updates the step-security/harden-runner GitHub Action from version 2.8.1 to 2.10.2 across multiple workflow files. The update includes security fixes, bug fixes, and new feature support for ARM runners.
No diagrams generated as the changes look simple and do not need a visual representation.
Change | Details | Files |
---|---|---|
Update harden-runner action version reference across all workflow files |
|
.github/workflows/build.yml .github/workflows/codeql.yml .github/workflows/coverage.yml .github/workflows/dependency-review.yml .github/workflows/scorecards.yml |
Incorporate security and functionality improvements from new harden-runner version |
|
.github/workflows/build.yml .github/workflows/codeql.yml .github/workflows/coverage.yml .github/workflows/dependency-review.yml .github/workflows/scorecards.yml |
Bumps step-security/harden-runner from 2.8.1 to 2.10.2.
Release notes
Sourced from step-security/harden-runner's releases.
Commits
0080882
Merge pull request #476 from step-security/rc-164a3a88b
Update dist556aae6
Merge pull request #480 from h0x0er/jatin/cleanup6c39b84
chore: clean the code40401cf
Update for isdocker806ab1c
Update check for isdocker2846811
update distdf8a07c
Merge pull request #475 from h0x0er/fix-execSync30636fb
bug fixes91182cc
Merge pull request #463 from step-security/rc-14Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show
Summary by Sourcery
CI: