An open index of dependabot pull requests across open source projects.

step-security/harden-runner

Ecosystem:
actions
Package URL:
pkg:githubactions/step-security/harden-runner
Total PRs:
8,233 Dependabot PRs
Latest PR:
about 8 hours ago
Unique Repositories:
2,633 repositories
Unique Repos (30 days):
251 repositories
Security Advisories
Harden-Runner: Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)
GHSA-cpmj-h4f6-r6pq CVE-2026-25598 MODERATE published 4 months ago • updated 2 days ago
## Summary A security vulnerability has been identified in the Harden-Runner GitHub Action (Community Tier) that allows outbound network connecti...
Harden-Runner has a command injection weaknesses in `setup.ts` and `arc-runner.ts`
GHSA-g85v-wf27-67xc CVE-2024-52587 LOW published over 1 year ago • updated about 2 months ago
### Summary Versions of step-security/harden-runner prior to v2.10.2 contain multiple command injection weaknesses via environment variables that ...
Egress Policy Bypass via DNS over HTTPS (DoH) in Harden-Runner (Community Tier)
GHSA-46g3-37rh-v698 CVE-2026-32947 MODERATE published 3 months ago • updated 2 days ago
## Summary A vulnerability exists in the Community Tier of Harden-Runner that allows bypassing the `egress-policy: block` network restriction usin...
Harden-Runner allows evasion of 'disable-sudo' policy
GHSA-mxr3-8whj-j74r CVE-2025-32955 MODERATE published about 1 year ago • updated 3 days ago
### Summary Harden-Runner includes a policy option `disable-sudo` to prevent the GitHub Actions runner user from using sudo. This is implemented by...
Egress Policy Bypass via DNS over TCP in Harden-Runner (Community Tier)
GHSA-g699-3x6g-wm3g CVE-2026-32946 MODERATE published 3 months ago • updated 7 days ago
## Summary A vulnerability exists in the Community Tier of Harden-Runner that allows bypassing the `egress-policy: block` network restriction usin...
Recent PRs
Package Details
Name: step-security/harden-runner
Ecosystem: actions
PURL Type: githubactions
Package URL: pkg:githubactions/step-security/harden-runner
JSON API: View JSON
Security Advisories

5

Active advisories
MODERATE 4
LOW 1
View All githubactions Advisories
Package Information
Description:

Harden-Runner provides runtime security for GitHub-hosted and self-hosted runners

Repository: https://github.com/step-security/harden-runner
Homepage: https://www.stepsecurity.io
Latest Release: v2.12.0
about 1 year ago
Dependent Repos: 497
Dependent Packages: 0
Ranking: Top 1.556% by dependent repos Top 0.0% by dependent pkgs
PR Status
Open 3,873 (47.0%)
Merged 1,994 (24.2%)
Closed 2,259 (27.4%)
PR Types
Major 10 (0.1%)
Minor 4,010 (48.7%)
Patch 4,105 (49.9%)