Skip to content

chore(deps): update step-security/harden-runner action to v2.18.0#505

Merged
renovate[bot] merged 1 commit intomasterfrom
renovate/step-security-harden-runner-2.x
Apr 23, 2026
Merged

chore(deps): update step-security/harden-runner action to v2.18.0#505
renovate[bot] merged 1 commit intomasterfrom
renovate/step-security-harden-runner-2.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 23, 2026

This PR contains the following updates:

Package Type Update Change Pending
step-security/harden-runner action minor v2.17.0v2.18.0 v2.19.0

Release Notes

step-security/harden-runner (step-security/harden-runner)

v2.18.0

Compare Source

What's Changed

Global Block List: During supply chain incidents like the recent axios and trivy compromises, StepSecurity will add known malicious domains and IP addresses (IOCs) to a global block list. These will be automatically blocked, even in audit mode, providing immediate protection without requiring any workflow changes.

Deploy on Self-Hosted VM: Added deploy-on-self-hosted-vm input that allows the Harden Runner agent to be installed directly on ephemeral self-hosted Linux runner VMs at workflow runtime. This is intended as an alternative when baking the agent into the VM image is not possible.

Full Changelog: step-security/harden-runner@v2.17.0...v2.18.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "after 10pm every weekday,before 5am every weekday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Apr 23, 2026
@github-actions github-actions Bot added the automation Changes to workflows label Apr 23, 2026
@sonarqubecloud
Copy link
Copy Markdown

@renovate renovate Bot merged commit a2f866a into master Apr 23, 2026
37 checks passed
@renovate renovate Bot deleted the renovate/step-security-harden-runner-2.x branch April 23, 2026 07:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automation Changes to workflows dependencies Pull requests that update a dependency file size/M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants