Skip to content

Update Harden Runner action#172

Merged
sjinks merged 1 commit into
trunkfrom
chore/update-harden-runner-security
May 29, 2026
Merged

Update Harden Runner action#172
sjinks merged 1 commit into
trunkfrom
chore/update-harden-runner-security

Conversation

@lancewillett
Copy link
Copy Markdown
Contributor

Summary

  • Updates step-security/harden-runner in the dependency review workflow from the floating v2 reference to v2.16.0.
  • Addresses the open Harden Runner Dependabot alerts in .github/workflows/dependency-review.yml.

Validation

  • ruby -e "require 'yaml'; YAML.load_file('.github/workflows/dependency-review.yml'); puts 'workflow yaml parsed'"
  • Confirmed v2.16.0 exists upstream.
  • git diff --check

Notes

  • This intentionally keeps the PR scoped to the alerted action. The older open Dependabot PRs for checkout, dependency-review-action, composer-install, and Composer packages are maintenance backlog, not current security-alert blockers.

@sonarqubecloud
Copy link
Copy Markdown

@lancewillett lancewillett requested review from rebeccahum and sjinks May 29, 2026 18:00
@sjinks sjinks self-assigned this May 29, 2026
@sjinks sjinks merged commit b76080e into trunk May 29, 2026
5 checks passed
@sjinks sjinks deleted the chore/update-harden-runner-security branch May 29, 2026 20:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants