Skip to content

chore(deps): bump step-security/harden-runner from 2.15.1 to 2.20.0#2407

Merged
manishdait merged 1 commit into
mainfrom
dependabot/github_actions/step-security/harden-runner-2.19.4
Jul 7, 2026
Merged

chore(deps): bump step-security/harden-runner from 2.15.1 to 2.20.0#2407
manishdait merged 1 commit into
mainfrom
dependabot/github_actions/step-security/harden-runner-2.19.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 7, 2026

Copy link
Copy Markdown
Contributor

Bumps step-security/harden-runner from 2.15.1 to 2.20.0.

Release notes

Sourced from step-security/harden-runner's releases.

v2.20.0

What's Changed

  • Support for block policy for MacOS and Windows GitHub-hosted runners
  • Support for Bitrise MacOS GitHub Actions runners
  • HTTPS monitoring support for Bun for Linux runners (enterprise tier)

Full Changelog: step-security/harden-runner@v2.19.4...v2.20.0

v2.19.4

What's Changed

  • Improvements for HTTPS Monitoring for the Enterprise tier of Harden Runner

Full Changelog: step-security/harden-runner@v2.19.3...v2.19.4

v2.19.3

What's Changed

Full Changelog: step-security/harden-runner@v2.19.2...v2.19.3

v2.19.2

What's Changed

  • Update the Harden Runner agent for enterprise tier to use go 1.26 and fix minor bugs.

Full Changelog: step-security/harden-runner@v2.19.1...v2.19.2

v2.19.1

What's Changed

What the fix changes

  • Harden-Runner will detect ubuntu-slim runners and exit cleanly with an informational log message, instead of post harden runner step failing on chown: invalid user: 'undefined'.

What the fix does not do

  • Jobs running on ubuntu-slim will not be monitored by Harden-Runner. The agent relies on kernel-level features (that require elevated capabilities).
  • Per GitHub's docs on single-CPU runners: "The container for ubuntu-slim runners runs in unprivileged mode. This means that some operations requiring elevated privileges such as mounting file systems, using Docker-in-Docker, or accessing low-level kernel features are not supported." Those low-level kernel features are what the agent needs, so monitoring inside the unprivileged container is not feasible today.

For StepSecurity enterprise customers If your security posture requires that workflows are always monitored, you can block the use of ubuntu-slim via workflow run policies see the Runner Label Policy docs. This lets you enforce that jobs only run on monitored runner types.

New Contributors

Full Changelog: step-security/harden-runner@v2.19.0...v2.19.1

v2.19.0

What's Changed

New Runner Support

... (truncated)

Commits
  • bf7454d Merge pull request #673 from step-security/fix/aggregate-error-startup-hang
  • 1188420 Update non-TLS agent to v0.16.2
  • 162cfea Update non-TLS agent to v0.16.1
  • eb9e1f4 Bring macOS runner updates from PR 674
  • 1a10b01 Update Windows agent to v1.0.7
  • 8b4a105 Apply npm audit fixes with release-age cooldown
  • 3626e03 Default TLS status check failures to enabled
  • 100e08b Update agent-ebpf to v1.8.12
  • 774f75f Update agent to v1.8.9
  • f312657 Extend missing-agent-dir guard to Linux and macOS cleanup paths
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 7, 2026
@dependabot
dependabot Bot requested review from a team as code owners July 7, 2026 08:53
@dependabot
dependabot Bot requested a review from exploreriii July 7, 2026 08:53
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 7, 2026
@dependabot
dependabot Bot requested a review from leninmehedy July 7, 2026 08:53
manishdait
manishdait previously approved these changes Jul 7, 2026
@github-actions github-actions Bot added open to community review PR is open for community review and feedback queue:committers PR awaiting committer technical review labels Jul 7, 2026
@dependabot dependabot Bot changed the title chore(deps): bump step-security/harden-runner from 2.15.1 to 2.19.4 chore(deps): bump step-security/harden-runner from 2.15.1 to 2.20.0 Jul 7, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/step-security/harden-runner-2.19.4 branch from cd5531a to a9c48a4 Compare July 7, 2026 14:00
@codecov

codecov Bot commented Jul 7, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

Impacted file tree graph

@@           Coverage Diff           @@
##             main    #2407   +/-   ##
=======================================
  Coverage   95.01%   95.01%           
=======================================
  Files         163      163           
  Lines       10465    10465           
=======================================
  Hits         9943     9943           
  Misses        522      522           
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@github-actions github-actions Bot added queue:junior-committer PR awaiting initial quality review and removed queue:committers PR awaiting committer technical review labels Jul 7, 2026
@aceppaluni aceppaluni added reviewer: maintainer PR needs a review from the maintainer team reviewer: committer request review help from a committer labels Jul 7, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/step-security/harden-runner-2.19.4 branch from a9c48a4 to e99111d Compare July 7, 2026 16:08
@manishdait

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.15.1 to 2.20.0.
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](step-security/harden-runner@v2.15.1...bf7454d)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-version: 2.19.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/step-security/harden-runner-2.19.4 branch from e99111d to 64ab34a Compare July 7, 2026 16:12
@github-actions github-actions Bot added queue:maintainers PR awaiting maintainer final review and removed queue:junior-committer PR awaiting initial quality review labels Jul 7, 2026
@manishdait
manishdait merged commit 7c2705c into main Jul 7, 2026
27 checks passed
@manishdait
manishdait deleted the dependabot/github_actions/step-security/harden-runner-2.19.4 branch July 7, 2026 16:48
@manishdait manishdait added this to the v0.2.8 milestone Jul 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code open to community review PR is open for community review and feedback queue:maintainers PR awaiting maintainer final review reviewer: committer request review help from a committer reviewer: maintainer PR needs a review from the maintainer team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants