step-security/harden-runner
actions
pkg:githubactions/step-security/harden-runner
8,233 Dependabot PRs
about 8 hours ago
2,633 repositories
251 repositories
Security Advisories
Harden-Runner: Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)
Harden-Runner has a command injection weaknesses in `setup.ts` and `arc-runner.ts`
Egress Policy Bypass via DNS over HTTPS (DoH) in Harden-Runner (Community Tier)
Harden-Runner allows evasion of 'disable-sudo' policy
Egress Policy Bypass via DNS over TCP in Harden-Runner (Community Tier)
Recent PRs
Chore: Bump step-security/harden-runner from 2.16.0 to 2.19.4
ci: bump the actions-minor-patch group across 1 directory with 5 updates
parley-wallet/parley-protocol-spec #11
build(deps): bump step-security/harden-runner from 2.19.0 to 2.19.4
utilitywarehouse/vault-kube-cloud-credentials #414
chore(ci)(deps): bump step-security/harden-runner from 2.19.1 to 2.19.4
dytsou/intern-corner-scheduler #103
chore(deps): bump the github-actions group across 1 directory with 5 updates
github-actions(deps): bump step-security/harden-runner from 2.4.0 to 2.19.4
chore(deps): bump the github-actions group across 1 directory with 15 updates
actions-marketplace-validations/afadesigns_zshellcheck #3
chore(deps): bump step-security/harden-runner from 2.19.3 to 2.19.4
eclipse-tractusx/tractusx-edc #2848
Bump the actions-updates group across 1 directory with 3 updates
chore(deps): bump step-security/harden-runner from 2.19.3 to 2.19.4
BcryptNet/bcrypt.net #293
deps(deps): Bump the actions group across 1 directory with 9 updates
chore(deps): bump the github-actions group across 1 directory with 12 updates
afadesigns/zshellcheck #1335
chore(deps): bump the github-actions-deps group across 1 directory with 3 updates
rudderlabs/rudder-sdk-node #424
Bump the actions-updates group across 1 directory with 2 updates
chore(deps): bump step-security/harden-runner from 2.14.1 to 2.19.4
Bump step-security/harden-runner from 2.15.0 to 2.19.4
lance0821/terraform-practice #27
Bump step-security/harden-runner from 2.19.3 to 2.19.4
Bump the production-dependencies group across 1 directory with 5 updates
Contrast-Security-OSS/contrast-documentation-rss #22
deps: bump step-security/harden-runner from 2.19.3 to 2.19.4
deps(deps): bump step-security/harden-runner from 2.19.3 to 2.19.4
markdown-confluence/markdown-confluence #737
Bump the dependencies group across 1 directory with 9 updates
oyakh1/hiero-mirror-node--034 #23
📦 deps: bump the actions-minor group with 7 updates
build(deps): bump the all group with 3 updates
kubernetes-sigs/cloud-provider-azure #10439
Chore: bump step-security/harden-runner from 2.19.2 to 2.19.4
chore(deps)(deps): bump step-security/harden-runner from 2.19.1 to 2.19.4
janitor-security/the-janitor #154
build(deps): Bump step-security/harden-runner from 2.19.1 to 2.19.4
devops-actions/github-copilot-pr-analysis #136
Bump step-security/harden-runner from 2.19.1 to 2.19.4
Chore(deps): Bump step-security/harden-runner from 2.19.2 to 2.19.4
chore(deps): bump step-security/harden-runner from 2.19.3 to 2.19.4
yolo-labz/claude-classroom-submit #26
Bump step-security/harden-runner from 2.19.1 to 2.19.4
JSPaste/Library #91
Bump step-security/harden-runner from 2.19.1 to 2.19.4
:seedling: Bump the github-actions group with 2 updates
open-cluster-management-io/ocm #1542
:seedling: Bump the github-actions group across 1 directory with 6 updates
ossf/scorecard #5071
Bump the dependencies group across 1 directory with 9 updates
oyakh1/hiero-mirror-node--047 #23
chore(deps): Bump the github-actions group with 2 updates
nullvariant/nullvariant-vscode-extensions #517
Bump step-security/harden-runner from 2.14.1 to 2.19.4
onap/dcaegen2-platform-ves-openapi-manager #6
chore(deps): bump step-security/harden-runner from 2.19.3 to 2.19.4
kaelys-js/heron #113
ci: bump the github-actions-minor-patch group with 4 updates
sebastienrousseau/dotfiles #906
Bump step-security/harden-runner from 2.9.1 to 2.19.4
cisco-open/AdversaryShield #53
Bump step-security/harden-runner from 2.19.1 to 2.19.4
chore(ci)(deps): bump step-security/harden-runner from 2.19.3 to 2.19.4 in the actions-all group
26zl/StudyWise #456
build(deps): Bump step-security/harden-runner from 2.19.3 to 2.19.4
FDio/csit #4151
build(deps): bump step-security/harden-runner from 2.19.2 to 2.19.4
FelipeFuhr/ffreis-k3s-vagrant #20
chore(deps): Bump step-security/harden-runner from 2.19.1 to 2.19.4
Takas0522/ComiCal #289
Bump step-security/harden-runner from 2.19.3 to 2.19.4
build(deps): bump the github-actions group across 1 directory with 3 updates
chore(actions): bump the actions group with 3 updates
daloyjs/daloy #23
build(deps): bump step-security/harden-runner from 2.19.3 to 2.19.4
Open-CMSIS-Pack/vidx2pidx #198
Package Details
| Name: | step-security/harden-runner |
| Ecosystem: | actions |
| PURL Type: | githubactions |
| Package URL: | pkg:githubactions/step-security/harden-runner |
| JSON API: | View JSON |
Security Advisories
Package Information
Harden-Runner provides runtime security for GitHub-hosted and self-hosted runners
| Repository: | https://github.com/step-security/harden-runner |
| Homepage: | https://www.stepsecurity.io |
| Latest Release: |
v2.12.0
about 1 year ago |
| Dependent Repos: | 497 |
| Dependent Packages: | 0 |
| Ranking: | Top 1.556% by dependent repos Top 0.0% by dependent pkgs |