Commit 179bead
authored
build(deps): update step-security/harden-runner action to v2.14.2 (#6)
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
|
[step-security/harden-runner](https://redirect.github.com/step-security/harden-runner)
| action | patch | `v2.14.0` → `v2.14.2` |
---
### Release Notes
<details>
<summary>step-security/harden-runner
(step-security/harden-runner)</summary>
###
[`v2.14.2`](https://redirect.github.com/step-security/harden-runner/releases/tag/v2.14.2)
[Compare
Source](https://redirect.github.com/step-security/harden-runner/compare/v2.14.1...v2.14.2)
##### What's Changed
Security fix: Fixed a medium severity vulnerability where outbound
network connections using sendto, sendmsg, and sendmmsg socket system
calls could bypass audit logging when using egress-policy: audit. This
issue only affects the Community Tier in audit mode; block mode and
Enterprise Tier were not affected. See
[GHSA-cpmj-h4f6-r6pq](https://redirect.github.com/step-security/harden-runner/security/advisories/GHSA-cpmj-h4f6-r6pq)
for details.
**Full Changelog**:
<step-security/harden-runner@v2.14.1...v2.14.2>
###
[`v2.14.1`](https://redirect.github.com/step-security/harden-runner/releases/tag/v2.14.1)
[Compare
Source](https://redirect.github.com/step-security/harden-runner/compare/v2.14.0...v2.14.1)
#### What's Changed
1. In some self-hosted environments, the agent could briefly fall back
to public DNS resolvers during startup if the system DNS was not yet
available. This behavior was unintended for GitHub-hosted runners and
has now been fixed to prevent any use of public DNS resolvers.
2. Fixed npm audit vulnerabilities
**Full Changelog**:
<step-security/harden-runner@v2.14.0...v2.14.1>
</details>
---
### Configuration
📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/go-krb5/x).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45NS4yIiwidXBkYXRlZEluVmVyIjoiNDIuOTUuMiIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6W119-->
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>1 parent 8200be9 commit 179bead
1 file changed
Lines changed: 2 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | | - | |
| 15 | + | |
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
| |||
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
44 | | - | |
| 44 | + | |
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
| |||
0 commit comments