wr-projects / monorepojs-scaffolding

💫 Tools to create JavaScript/TypeScript monorepos based on open source standards and best practices to create NodeJS packages.
MIT License
0 stars 0 forks source link

⬆️upgrade(ci): Bump step-security/harden-runner from 2.2.0 to 2.4.1 in /.github/workflows #41

Closed dependabot[bot] closed 1 year ago

dependabot[bot] commented 1 year ago

Bumps step-security/harden-runner from 2.2.0 to 2.4.1.

Release notes

Sourced from step-security/harden-runner's releases.

v2.4.1

What's Changed

Release v2.4.1 by @​varunsh-coder and @​Devils-Knight in step-security/harden-runner#309

This release

  1. Shows a preview of the network events in the job summary markdown
  2. Uses a fallback DNS service from Cloudflare in addition to Google DNS to improve reliability

Full Changelog: https://github.com/step-security/harden-runner/compare/v2...v2.4.1

v2.4.0

What's Changed

Full Changelog: https://github.com/step-security/harden-runner/compare/v2...v2.4.0

v2.3.1

What's Changed

Full Changelog: https://github.com/step-security/harden-runner/compare/v2...v2.3.1

v2.3.0

What's Changed

Full Changelog: https://github.com/step-security/harden-runner/compare/v2...v2.3.0

v2.2.1

What's Changed

  • Fix issue to get cache endpoint by @​h0x0er in step-security/harden-runner#253 Harden runner has the ability to automatically detect the cache endpoint used by each job. When Harden runner is used in block mode, this endpoint is added to the list of allowed endpoints. A fix has been implemented to improve this feature by updating the logic used to fetch the cache endpoint. This update involves using code from the actions/cache library to ensure the endpoint is properly retrieved.

... (truncated)

Commits
  • 55d479f Release v2.4.1 (#309)
  • 215c5ca Merge pull request #307 from step-security/dependabot/github_actions/github/c...
  • 95a625a Merge pull request #306 from step-security/dependabot/github_actions/actions/...
  • 7d83e8e Bump github/codeql-action from 2.3.3 to 2.13.4
  • 36ccae2 Bump actions/checkout from 3.5.2 to 3.5.3
  • beefd8c Merge pull request #295 from step-security/dependabot/github_actions/github/c...
  • bb523fd Merge pull request #301 from step-security/dependabot/github_actions/codecov/...
  • 760976e Bump codecov/codecov-action from 3.1.2 to 3.1.4
  • f702486 Merge pull request #300 from step-security/ak-codewise-dogfooding
  • 1f715fe using ai-codewise int for dogfooding
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
dependabot[bot] commented 1 year ago

The following labels could not be found: source:💚github_actions, source:🤖bot.

CLAassistant commented 1 year ago

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

github-actions[bot] commented 1 year ago

The Pull Request has been marked as stale due to inactivity. Please show activity within 8 days or it will be automatically closed.

dependabot[bot] commented 1 year ago

Superseded by #45.