Skip to content

Bump step-security/harden-runner from 2.11.0 to 2.13.0 - #116

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/step-security/harden-runner-2.13.0
Closed

Bump step-security/harden-runner from 2.11.0 to 2.13.0#116
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/step-security/harden-runner-2.13.0

Bump step-security/harden-runner from 2.11.0 to 2.13.0

ed9b6b7
Select commit
Loading
Failed to load commit list.
This check has been archived and is scheduled for deletion. Learn more about checks retention
StepSecurity Actions Security / StepSecurity Harden-Runner succeeded Jul 16, 2025 in 30m 4s

No anomalous activity on CI/CD runners

No new Harden-Runner detections for this pull request.

Details

Harden-Runner monitors all outbound traffic from each job at the DNS and network layers to ensure that CI/CD runners do not communicate with unauthorized destinations.
This reduces the risk of CI/CD secrets and source code being exfiltrated.

📋 Monitored GitHub Actions workflow runs

The following GitHub Actions workflow runs were monitored as part of this pull request.

Workflow Run ID Unique Destinations Actions Used Detailed Insights
test.yml 17609145180 1 3 View Insights
multi-job-example.yml 16315633564 2 2 View Insights
matrix-example.yml 16315633531 1 2 View Insights
multi-job-example.yml 16315632665 1 2 View Insights
guarddog.yml 16315633723 - - Harden-Runner not enabled
codeql.yml 16315633597 2 3 View Insights
test.yml 16315632655 1 3 View Insights
test.yml 16315633532 1 3 View Insights
dependency-review.yml 16315633552 3 3 View Insights

📚 Learn More

You can learn more about this GitHub check here