Below you will find pages that utilize the taxonomy term “step-security”
November 19, 2024
Harden-Runner
Version updated for step-security/harden-runner to version v2.10.2.
This publisher is shown as ‘verified’ by GitHub. This action is used across all versions by 4,683 repositories. Go to the GitHub Marketplace to find the latest changes.
Release notes What’s Changed Fixes low-severity command injection weaknesses The advisory is here: https://github.com/step-security/harden-runner/security/advisories/GHSA-g85v-wf27-67xc
Bug fix to improve detection of whether Harden-Runner is running in a container
Full Changelog: https://github.com/step-security/harden-runner/compare/v2...v2.10.2
September 11, 2024
Harden-Runner
Version updated for step-security/harden-runner to version v2.10.1.
This publisher is shown as ‘verified’ by GitHub. This action is used across all versions by 4,030 repositories. Go to the GitHub Marketplace to find the latest changes.
Release notes What’s Changed Release v2.10.1 by @varunsh-coder in https://github.com/step-security/harden-runner/pull/463 Bug fix: Resolves an issue where DNS resolution of .local domains was failing when using a Kind cluster in a GitHub Actions workflow.
Full Changelog: https://github.
September 11, 2024
Harden-Runner
Version updated for step-security/harden-runner to version v2.10.0.
This publisher is shown as ‘verified’ by GitHub. This action is used across all versions by 4,026 repositories. Go to the GitHub Marketplace to find the latest changes.
Release notes What’s Changed Release v2.10.0 by @h0x0er and @varunsh-coder in https://github.com/step-security/harden-runner/pull/455
ARM Support: Harden-Runner Enterprise tier now supports GitHub-hosted ARM runners. This includes all the features that apply to previously supported GitHub-hosted x64 Linux runners.
August 6, 2024
Harden-Runner
Version updated for step-security/harden-runner to version v2.9.1.
This publisher is shown as ‘verified’ by GitHub. This action is used across all versions by 3,813 repositories. Go to the GitHub Marketplace to find the latest changes.
Release notes What’s Changed Release v2.9.1 by @h0x0er and @varunsh-coder in #440 This release includes two changes:
Updated markdown displayed in the job summary by the Harden-Runner Action. Fixed a bug affecting Enterprise Tier customers where the agent attempted to upload telemetry for jobs with disable-telemetry set to true.
July 19, 2024
Harden-Runner
Version updated for step-security/harden-runner to version v2.9.0.
This publisher is shown as ‘verified’ by GitHub. This action is used across all versions by 3,710 repositories. Go to the GitHub Marketplace to find the latest changes.
Release notes What’s Changed Release v2.9.0 by @h0x0er and @varunsh-coder in https://github.com/step-security/harden-runner/pull/435 This release includes:
Enterprise Tier - Telemetry Upload Enhancement: For the enterprise tier, this change helps overcome size constraints, allowing for more reliable telemetry uploads from the Harden-Runner agent to the StepSecurity backend API.
June 14, 2024
Wait for secrets
Version updated for step-security/wait-for-secrets to version v1.2.0.
This publisher is shown as ‘verified’ by GitHub. This action is used across all versions by 37 repositories. Go to the GitHub Marketplace to find the latest changes.
Release notes What’s Changed Bump step-security/harden-runner from 2.0.0 to 2.1.0 by @dependabot in https://github.com/step-security/wait-for-secrets/pull/81 Bump github/codeql-action from 2.1.37 to 2.1.38 by @dependabot in https://github.com/step-security/wait-for-secrets/pull/80 Bump codecov/codecov-action from 2.1.0 to 3.1.1 by @dependabot in https://github.com/step-security/wait-for-secrets/pull/79 Bump actions/checkout from 3.
June 7, 2024
Harden-Runner
Version updated for step-security/harden-runner to version v2.8.1.
This publisher is shown as ‘verified’ by GitHub. This action is used across all versions by 3,425 repositories. Go to the GitHub Marketplace to find the latest changes.
Release notes What’s Changed Bug fix: Update isGitHubHosted implementation by @varunsh-coder in https://github.com/step-security/harden-runner/pull/425 The previous implementation incorrectly identified large GitHub-hosted runners as self-hosted runners. As a result, harden-runner was not executing on these large GitHub-hosted runners.
April 30, 2024
Harden-Runner
Version updated for step-security/harden-runner to version v2.7.1.
This publisher is shown as ‘verified’ by GitHub. This action is used across all versions by 3,064 repositories. Go to the GitHub Marketplace to find the latest changes.
Release notes What’s Changed Release v2.7.1 by @varunsh-coder, @h0x0er, @ashishkurmi in https://github.com/step-security/harden-runner/pull/397 This release:
Improves the capability to inspect outbound HTTPS traffic on GitHub-hosted and self-hosted VM runners Updates README to add link to case study video on how Harden-Runner detected a supply chain attack on a Google open-source project Addresses minor bugs Full Changelog: https://github.
November 17, 2023
Harden-Runner
Version updated for step-security/harden-runner to version v2.6.1.
This publisher is shown as ‘verified’ by GitHub. This action is used across all versions by 1,907 repositories. Go to the GitHub Marketplace to find the latest changes.
Release notes What’s Changed Release v2.6.1 by @varunsh-coder and @h0x0er in https://github.com/step-security/harden-runner/pull/356 This release:
Improves the job summary markdown written by the Harden-Runner Action Improves detection of cache endpoint used by the job Detects use of Kubernetes mode in Actions Runner Controller (ARC) based runners Updates dependencies Full Changelog: https://github.
October 3, 2023
Harden-Runner
Version updated for step-security/harden-runner to version v2.6.0.
This publisher is shown as erified by GitHub. This action is used across all versions by 1,620 repositories. Go to the GitHub Marketplace to find the latest changes.
Release notes What’s Changed Release v2.6.0 by @varunsh-coder in https://github.com/step-security/harden-runner/pull/346
This release adds support for self-hosted Virtual Machine runners (e.g. on EC2).
Both ephemeral and persistent self-hosted VM runners are supported Documentation: https://docs.stepsecurity.io/harden-runner/how-tos/enable-runtime-security-vm Full Changelog: https://github.
August 10, 2023
Harden Runner
Version updated for step-security/harden-runner to version v2.5.1. This action is used across all versions by 1,320 repositories.
Go to the GitHub Marketplace to find the latest changes.