Repository navigation
Bump step-security/harden-runner from 2.21.0 to 2.21.1 - #40
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.21.0 to 2.21.1. - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@05e3151...e14015d) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.21.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
|
PR: #40 Note: This metadata is also included in the Gerrit commit message for reconciliation. |
|
Change raised in Gerrit by GitHub2Gerrit: https://gerrit.onap.org/r/c/usecase-ui/+/147614 |
## Release notes Sourced from step-security/harden-runner's releases. v2.21.1 What's Changed Improved performance of the disable-sudo feature. Fixed an issue in the Community tier where new endpoints required by the GitHub Actions runner were not being implicitly allowed in block mode. Fixed the Harden-Runner post step failing on Linux distributions that do not have a merged /usr filesystem layout (for example Debian 11), where /usr/bin/echo does not exist. This mainly affected self-hosted runners. Documentation updates: clarified which features are in the Community (free) vs Enterprise tier. Full Changelog: step-security/harden-runner@v2.21.0...v2.21.1 ## Commits e14015d Merge pull request #690 from step-security/rc-43 9001249 docs: update harden-runner version pin to v2.21.0 in getting started example a447fba docs: expand enterprise feature list and document custom VM and ubuntu-slim l b0eaf8d docs: clarify community vs enterprise tiers and add maintained actions section 063e8e3 Merge pull request #687 from rohan-stepsecurity/rp/fix/bin-echo-fallback f46bdc1 chore: bump agent-ebpf to v1.9.1 and agent to v0.16.3 42e6daa fix: fall back to /bin/echo for non-usr-merged distros See full diff in compare view  Issue-ID: CIMAN-33 Signed-off-by: dependabot[bot] <support@github.com> Change-Id: Id1b8efdf67aff7b4a242d7c24a6aaac561b330c5 GitHub-PR: #40 GitHub-Hash: ca5f1e0908961937 Signed-off-by: onap.gh2gerrit <releng+onap-gh2gerrit@linuxfoundation.org>
|
Automated PR Closure This pull request has been automatically closed by GitHub2Gerrit. The corresponding Gerrit change has been accepted and merged ✅ The changes from this PR are now part of the main codebase in Gerrit. This is an automated action performed by the GitHub2Gerrit tool. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps step-security/harden-runner from 2.21.0 to 2.21.1.
Release notes
Sourced from step-security/harden-runner's releases.
Commits
e14015dMerge pull request #690 from step-security/rc-439001249docs: update harden-runner version pin to v2.21.0 in getting started examplea447fbadocs: expand enterprise feature list and document custom VM and ubuntu-slim l...b0eaf8ddocs: clarify community vs enterprise tiers and add maintained actions section063e8e3Merge pull request #687 from rohan-stepsecurity/rp/fix/bin-echo-fallbackf46bdc1chore: bump agent-ebpf to v1.9.1 and agent to v0.16.342e6daafix: fall back to/bin/echofor non-usr-merged distrosDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)