Skip to content

build(deps): bump the actions group across 1 directory with 3 updates#251

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-d4b2bac322
Open

build(deps): bump the actions group across 1 directory with 3 updates#251
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-d4b2bac322

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 22, 2026

Copy link
Copy Markdown
Contributor

Bumps the actions group with 3 updates in the / directory: step-security/harden-runner, step-security/action-slack-notify and zizmorcore/zizmor-action.

Updates step-security/harden-runner from 2.19.0 to 2.20.0

Release notes

Sourced from step-security/harden-runner's releases.

v2.20.0

What's Changed

  • Support for block policy for MacOS and Windows GitHub-hosted runners
  • Support for Bitrise MacOS GitHub Actions runners
  • HTTPS monitoring support for Bun for Linux runners (enterprise tier)

Full Changelog: step-security/harden-runner@v2.19.4...v2.20.0

v2.19.4

What's Changed

  • Improvements for HTTPS Monitoring for the Enterprise tier of Harden Runner

Full Changelog: step-security/harden-runner@v2.19.3...v2.19.4

v2.19.3

What's Changed

Full Changelog: step-security/harden-runner@v2.19.2...v2.19.3

v2.19.2

What's Changed

  • Update the Harden Runner agent for enterprise tier to use go 1.26 and fix minor bugs.

Full Changelog: step-security/harden-runner@v2.19.1...v2.19.2

v2.19.1

What's Changed

What the fix changes

  • Harden-Runner will detect ubuntu-slim runners and exit cleanly with an informational log message, instead of post harden runner step failing on chown: invalid user: 'undefined'.

What the fix does not do

  • Jobs running on ubuntu-slim will not be monitored by Harden-Runner. The agent relies on kernel-level features (that require elevated capabilities).
  • Per GitHub's docs on single-CPU runners: "The container for ubuntu-slim runners runs in unprivileged mode. This means that some operations requiring elevated privileges such as mounting file systems, using Docker-in-Docker, or accessing low-level kernel features are not supported." Those low-level kernel features are what the agent needs, so monitoring inside the unprivileged container is not feasible today.

For StepSecurity enterprise customers If your security posture requires that workflows are always monitored, you can block the use of ubuntu-slim via workflow run policies see the Runner Label Policy docs. This lets you enforce that jobs only run on monitored runner types.

New Contributors

Full Changelog: step-security/harden-runner@v2.19.0...v2.19.1

Commits
  • bf7454d Merge pull request #673 from step-security/fix/aggregate-error-startup-hang
  • 1188420 Update non-TLS agent to v0.16.2
  • 162cfea Update non-TLS agent to v0.16.1
  • eb9e1f4 Bring macOS runner updates from PR 674
  • 1a10b01 Update Windows agent to v1.0.7
  • 8b4a105 Apply npm audit fixes with release-age cooldown
  • 3626e03 Default TLS status check failures to enabled
  • 100e08b Update agent-ebpf to v1.8.12
  • 774f75f Update agent to v1.8.9
  • f312657 Extend missing-agent-dir guard to Linux and macOS cleanup paths
  • Additional commits viewable in compare view

Updates step-security/action-slack-notify from 2.3.5 to 2.4.0

Release notes

Sourced from step-security/action-slack-notify's releases.

v2.4.0

What's Changed

New Contributors

Full Changelog: step-security/action-slack-notify@v2...v2.4.0

v2.3.6

What's Changed

New Contributors

Full Changelog: step-security/action-slack-notify@v2...v2.3.6

Commits
  • e4cdee1 Merge pull request #60 from step-security/Raj-StepSecurity-patch-8
  • 7e52924 feat: Update action.yml with docker published image
  • df6752c Merge pull request #59 from step-security/auto-cherry-pick
  • 3948001 Bump alpine from 865b95f to 5b10f43
  • 69ab608 Remove message title when MSG_MINIMAL is true Done
  • 36e490f Bump alpine from 51183f2 to 865b95f
  • 7d21461 Bump alpine from 56fa17d to 51183f2
  • e336b0f Clarify ENABLE_ESCAPES behaviour in readme
  • 7210d1a Merge pull request #58 from step-security/Raj-StepSecurity-patch-7
  • 558bd1f feat: Update action.yml
  • Additional commits viewable in compare view

Updates zizmorcore/zizmor-action from 0.5.3 to 0.6.0

Release notes

Sourced from zizmorcore/zizmor-action's releases.

v0.6.0

zizmor 1.27.0 is now the default version used by the action.

What's Changed

New Contributors

Full Changelog: zizmorcore/zizmor-action@v0.5.7...v0.6.0

v0.5.7

1.26.1 is now available via the action 1.26.1 is now the default version of zizmor used by the action

v0.5.6

  • 1.25.2 is now available via the action
  • 1.25.2 is now the default version of zizmor used by the action

v0.5.5

This is a no-op release.

v0.5.4

  • 1.25.0 is now available via the action
  • 1.25.0 is now the default version of zizmor used by the action
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jun 22, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-d4b2bac322 branch from 7b0079a to ef40416 Compare June 29, 2026 22:43
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-d4b2bac322 branch 2 times, most recently from 56383da to ec84373 Compare July 13, 2026 22:43
Bumps the actions group with 3 updates in the / directory: [step-security/harden-runner](https://github.com/step-security/harden-runner), [step-security/action-slack-notify](https://github.com/step-security/action-slack-notify) and [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action).


Updates `step-security/harden-runner` from 2.19.0 to 2.20.0
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](step-security/harden-runner@8d3c67d...bf7454d)

Updates `step-security/action-slack-notify` from 2.3.5 to 2.4.0
- [Release notes](https://github.com/step-security/action-slack-notify/releases)
- [Commits](step-security/action-slack-notify@e04c77a...e4cdee1)

Updates `zizmorcore/zizmor-action` from 0.5.3 to 0.6.0
- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)
- [Commits](zizmorcore/zizmor-action@b1d7e1f...6599ee8)

---
updated-dependencies:
- dependency-name: step-security/action-slack-notify
  dependency-version: 2.3.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: step-security/harden-runner
  dependency-version: 2.19.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: zizmorcore/zizmor-action
  dependency-version: 0.5.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-d4b2bac322 branch from ec84373 to c21a93b Compare July 20, 2026 22:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants