An open index of dependabot pull requests across open source projects.

build(deps): Bump step-security/harden-runner from 2.19.1 to 2.19.4

Closed
Number: #136
Type: Pull Request
State: Closed
Author: dependabot[bot] dependabot[bot]
Association: Unknown
Comments: 2
Created: May 25, 2026 at 09:28 PM UTC
(18 days ago)
Updated: May 25, 2026 at 09:28 PM UTC
(18 days ago)
Closed: May 25, 2026 at 09:28 PM UTC
(18 days ago)
Time to Close: less than a minute
Labels:
dependencies github_actions
Description:

Bumps step-security/harden-runner from 2.19.1 to 2.19.4.

Release notes

Sourced from step-security/harden-runner's releases.

v2.19.4

What's Changed

  • Improvements for HTTPS Monitoring for the Enterprise tier of Harden Runner

Full Changelog: https://github.com/step-security/harden-runner/compare/v2.19.3...v2.19.4

v2.19.3

What's Changed

Full Changelog: https://github.com/step-security/harden-runner/compare/v2.19.2...v2.19.3

v2.19.2

What's Changed

  • Update the Harden Runner agent for enterprise tier to use go 1.26 and fix minor bugs.

Full Changelog: https://github.com/step-security/harden-runner/compare/v2.19.1...v2.19.2

Commits
  • 9af89fc Merge pull request #667 from step-security/update-agent-v1.8.6
  • 485dce8 Update agent to v1.8.6
  • ab7a940 Merge pull request #665 from step-security/fix/use-policy-store-default-audit
  • ec41b78 Default to audit mode when api-key missing with use-policy-store
  • 9ca718d Merge pull request #664 from step-security/update-agent-v1.8.5
  • 1dee3df Update agent to v1.8.5
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Package Dependencies
Ecosystem:
actions
Version Change:
2.19.1 → 2.19.4
Update Type:
Patch
Technical Details
ID: 15921905
UUID: 4519624199
Node ID: PR_kwDOQgo_qs7fLN_Y
Host: GitHub
Repository: devops-actions/github-copilot-pr-analysis