build(deps): bump the actions group across 1 directory with 3 updates#251
Open
dependabot[bot] wants to merge 1 commit into
Open
build(deps): bump the actions group across 1 directory with 3 updates#251dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
dependabot
Bot
force-pushed
the
dependabot/github_actions/actions-d4b2bac322
branch
from
June 29, 2026 22:43
7b0079a to
ef40416
Compare
dependabot
Bot
force-pushed
the
dependabot/github_actions/actions-d4b2bac322
branch
2 times, most recently
from
July 13, 2026 22:43
56383da to
ec84373
Compare
Bumps the actions group with 3 updates in the / directory: [step-security/harden-runner](https://github.com/step-security/harden-runner), [step-security/action-slack-notify](https://github.com/step-security/action-slack-notify) and [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action). Updates `step-security/harden-runner` from 2.19.0 to 2.20.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@8d3c67d...bf7454d) Updates `step-security/action-slack-notify` from 2.3.5 to 2.4.0 - [Release notes](https://github.com/step-security/action-slack-notify/releases) - [Commits](step-security/action-slack-notify@e04c77a...e4cdee1) Updates `zizmorcore/zizmor-action` from 0.5.3 to 0.6.0 - [Release notes](https://github.com/zizmorcore/zizmor-action/releases) - [Commits](zizmorcore/zizmor-action@b1d7e1f...6599ee8) --- updated-dependencies: - dependency-name: step-security/action-slack-notify dependency-version: 2.3.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: step-security/harden-runner dependency-version: 2.19.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: zizmorcore/zizmor-action dependency-version: 0.5.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/github_actions/actions-d4b2bac322
branch
from
July 20, 2026 22:43
ec84373 to
c21a93b
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the actions group with 3 updates in the / directory: step-security/harden-runner, step-security/action-slack-notify and zizmorcore/zizmor-action.
Updates
step-security/harden-runnerfrom 2.19.0 to 2.20.0Release notes
Sourced from step-security/harden-runner's releases.
Commits
bf7454dMerge pull request #673 from step-security/fix/aggregate-error-startup-hang1188420Update non-TLS agent to v0.16.2162cfeaUpdate non-TLS agent to v0.16.1eb9e1f4Bring macOS runner updates from PR 6741a10b01Update Windows agent to v1.0.78b4a105Apply npm audit fixes with release-age cooldown3626e03Default TLS status check failures to enabled100e08bUpdate agent-ebpf to v1.8.12774f75fUpdate agent to v1.8.9f312657Extend missing-agent-dir guard to Linux and macOS cleanup pathsUpdates
step-security/action-slack-notifyfrom 2.3.5 to 2.4.0Release notes
Sourced from step-security/action-slack-notify's releases.
Commits
e4cdee1Merge pull request #60 from step-security/Raj-StepSecurity-patch-87e52924feat: Update action.yml with docker published imagedf6752cMerge pull request #59 from step-security/auto-cherry-pick3948001Bump alpine from865b95fto5b10f4369ab608Remove message title when MSG_MINIMAL is true Done36e490fBump alpine from51183f2to865b95f7d21461Bump alpine from56fa17dto51183f2e336b0fClarify ENABLE_ESCAPES behaviour in readme7210d1aMerge pull request #58 from step-security/Raj-StepSecurity-patch-7558bd1ffeat: Update action.ymlUpdates
zizmorcore/zizmor-actionfrom 0.5.3 to 0.6.0Release notes
Sourced from zizmorcore/zizmor-action's releases.
Commits
6599ee8Addcollectinput (#139)bec05c8Sync zizmor versions (#137)cf59549Add issue templates (#135)f72bf17chore(deps): bump github/codeql-action/upload-sarif (#134)b2a6facci: block version sync workflow on forks (#129)2d88f44Readme: document missing inputs (#130)d81e276Fold Docker image pull output into a collapsed Actions log group (#132)8c13c53chore(deps): bump the github-actions group with 2 updates (#133)2f8e9c6README: bump versions (#128)192e21dSync zizmor versions (#127)