Sourced from step-security/harden-runner's releases.
v2.12.0
What's Changed
A new option,
disable-sudo-and-containers, is now available to replace thedisable-sudo policy, addressing Docker-based privilege escalation (CVE-2025-32955). More details can be found in this blog post.New detections have been added based on insights from the tj-actions and reviewdog actions incidents.
Full Changelog: https://github.com/step-security/harden-runner/compare/v2...v2.12.0
0634a26
Merge pull request #541
from step-security/rc-202e3c511
Update action.yml40873e6
Update README.md484c279
Update README.md4c8582f
Update agent versionse8d595c
fix disable_sudo_and_containers bug5d277fc
fix journalctl related bugff2ab22
Merge pull request #536
from rohan-stepsecurity/feat/flag/disable-sudo-and-co...b81d650
fix: run sudo command only when both disable-sudo and
disable-sudo-and-docker...769df4e
Update agentSourced from google-github-actions/auth's releases.
v2.1.10
What's Changed
- Declare workflow permissions by
@sethvargoin google-github-actions/auth#482- Document that the OIDC token expires in 5min by
@sethvargoin google-github-actions/auth#483- Release: v2.1.10 by
@google-github-actions-botin google-github-actions/auth#484Full Changelog: https://github.com/google-github-actions/auth/compare/v2.1.9...v2.1.10
v2.1.9
What's Changed
- Use our custom boolean parsing by
@sethvargoin google-github-actions/auth#478- Update deps by
@sethvargoin google-github-actions/auth#479- Release: v2.1.9 by
@google-github-actions-botin google-github-actions/auth#480Full Changelog: https://github.com/google-github-actions/auth/compare/v2.1.8...v2.1.9
Sourced from actions/download-artifact's releases.
v4.3.0
What's Changed
- feat: implement new
artifact-idsinput by@GrantBirkiin actions/download-artifact#401- Fix workflow example for downloading by artifact ID by
@joshmgrossin actions/download-artifact#402- Prep for v4.3.0 release by
@robherleyin actions/download-artifact#404New Contributors
@GrantBirkimade their first contribution in actions/download-artifact#401Full Changelog: https://github.com/actions/download-artifact/compare/v4.2.1...v4.3.0
d3f86a1
Merge pull request #404
from actions/robherley/v4.3.0fc02353
prep for v4.3.0 release7745437
Merge pull request #402
from actions/joshmgross/download-by-id-example84fc7a0
Remove path filters from Check dist workflow67f2bc3
Fix workflow example for downloading by artifact ID8ea3c2c
Merge pull request #401
from actions/download-by-idd219c63
add supporting unit tests for artifact downloads with ids54124fb
revert getArtifact() changes - for now we have to list and
filter by artifa...b83057b
bundle171183c
use the same artifactClient.getArtifact structure as seen
above in `isSingl...Sourced from actions/attest's releases.
v2.3.0
What's Changed
- Bump
@octokit/requestfrom 8.2.0 to 8.4.1 by@dependabotin actions/attest#229- Bump
@sigstore/ocifrom 0.4.0 to 0.5.0 by@bdehamerin actions/attest#235
- Adds support for reading the
HttpHeadersvalue from the Docker config fileFull Changelog: https://github.com/actions/attest/compare/v2...v2.3.0
afd6382
Bump @sigstore/oci from 0.4.0 to 0.5.0 (#235)d731111
Bump the npm-development group across 1 directory with 6 updates (#234)13aa4f6
Bump @octokit/request from 8.2.0 to 8.4.1 (#229)129b656
Bump the npm-development group with 3 updates (#227)f3c169c
Bump the npm-development group with 5 updates (#225)48e991b
Bump the npm-development group across 1 directory with 6 updates (#223)Sourced from tj-actions/changed-files's changelog.
Changelog
46.0.5 - (2025-04-09)
⚙️ Miscellaneous Tasks
- deps: Bump yaml from 2.7.0 to 2.7.1 (#2520) (ed68ef8) - (dependabot[bot])
- deps-dev: Bump typescript from 5.8.2 to 5.8.3 (#2516) (a7bc14b) - (dependabot[bot])
- deps-dev: Bump
@types/nodefrom 22.13.11 to 22.14.0 (#2517) (3d751f6) - (dependabot[bot])- deps-dev: Bump eslint-plugin-prettier from 5.2.3 to 5.2.6 (#2519) (e2fda4e) - (dependabot[bot])
- deps-dev: Bump ts-jest from 29.2.6 to 29.3.1 (#2518) (0bed1b1) - (dependabot[bot])
- deps: Bump github/codeql-action from 3.28.12 to 3.28.15 (#2530) (6802458) - (dependabot[bot])
- deps: Bump tj-actions/branch-names from 8.0.1 to 8.1.0 (#2521) (cf2e39e) - (dependabot[bot])
- deps: Bump tj-actions/verify-changed-files from 20.0.1 to 20.0.4 (#2523) (6abeaa5) - (dependabot[bot])
⬆️ Upgrades
- Upgraded to v46.0.4 (#2511)
Co-authored-by: github-actions[bot] (6f67ee9) - (github-actions[bot])
46.0.4 - (2025-04-03)
🐛 Bug Fixes
- Bug modified_keys and changed_key outputs not set when no changes detected (#2509) (6cb76d0) - (Tonye Jack)
📚 Documentation
⬆️ Upgrades
- Upgraded to v46.0.3 (#2506)
Co-authored-by: github-actions[bot] Co-authored-by: Tonye Jack jtonye@ymail.com (27ae6b3) - (github-actions[bot])
46.0.3 - (2025-03-23)
🔄 Update
- Updated README.md (#2501)
Co-authored-by: github-actions[bot] (41e0de5) - (github-actions[bot])
- Updated README.md (#2499)
Co-authored-by: github-actions[bot] (9457878) - (github-actions[bot])
📚 Documentation
... (truncated)
5426ecc
chore(deps): bump actions/download-artifact from 4.2.1 to 4.3.0 (#2545)513a44e
chore(deps-dev): bump @types/node from 22.14.1 to 22.15.0
(#2544)46e217d
chore(deps): bump github/codeql-action from 3.28.15 to 3.28.16 (#2542)c34c1c1
chore(deps): bump actions/setup-node from 4.3.0 to 4.4.0 (#2539)52c3beb
chore(deps-dev): bump ts-jest from 29.3.1 to 29.3.2 (#2536)ea3010b
chore(deps-dev): bump @types/node from 22.14.0 to 22.14.1
(#2537)be393a9
remove: commit and push step from build job (#2538)9b4bb2b
chore(deps): bump tj-actions/branch-names from 8.1.0 to 8.2.1 (#2535)135667e
Merge pull request #122
from nix-community/118-bug-cant-save-a-cachee29de90
chore: build the action6bd39b8
fix(action): use TarCommandModifiers1b6f675
chore(deps): update buildjet/toolkit2b45b8c
chore(deps): update actions/toolkitf68581e
chore: build the actionb6406dc
Merge pull request #117
from nix-community/116-bug-inputsgcmaxstoresizevalue-...a918219
chore: build the actionc6081ef
feat(ci): add example of large gc-max-store-sizecf6af9e
fix(action): use bigint for the store sizeSourced from github/codeql-action's releases.
v3.28.16
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.16 - 23 Apr 2025
- Update default CodeQL bundle version to 2.21.1. #2863
See the full CHANGELOG.md for more information.
Sourced from github/codeql-action's changelog.
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
No user facing changes.
3.28.16 - 23 Apr 2025
- Update default CodeQL bundle version to 2.21.1. #2863
3.28.15 - 07 Apr 2025
- Fix bug where the action would fail if it tried to produce a debug artifact with more than 65535 files. #2842
3.28.14 - 07 Apr 2025
- Update default CodeQL bundle version to 2.21.0. #2838
3.28.13 - 24 Mar 2025
No user facing changes.
3.28.12 - 19 Mar 2025
- Dependency caching should now cache more dependencies for Java
build-mode: noneextractions. This should speed up workflows and avoid inconsistent alerts in some cases.- Update default CodeQL bundle version to 2.20.7. #2810
3.28.11 - 07 Mar 2025
- Update default CodeQL bundle version to 2.20.6. #2793
3.28.10 - 21 Feb 2025
- Update default CodeQL bundle version to 2.20.5. #2772
- Address an issue where the CodeQL Bundle would occasionally fail to decompress on macOS. #2768
3.28.9 - 07 Feb 2025
- Update default CodeQL bundle version to 2.20.4. #2753
3.28.8 - 29 Jan 2025
- Enable support for Kotlin 2.1.10 when running with CodeQL CLI v2.20.3. #2744
3.28.7 - 29 Jan 2025
No user facing changes.
... (truncated)
28deaed
Merge pull request #2865
from github/update-v3.28.16-2a8cbadc003c5d71
Update changelog for v3.28.162a8cbad
Merge pull request #2863
from github/update-bundle/codeql-bundle-v2.21.1f76eaf5
Add changelog notee63b3f5
Update default bundle to codeql-bundle-v2.21.14c3e536
Merge pull request #2853
from github/dependabot/npm_and_yarn/npm-7d84c66b6656dd02f
Merge pull request #2852
from github/dependabot/github_actions/actions-457587...192406d
Merge branch 'main' into
dependabot/github_actions/actions-4575878e06c7dbb20
Merge pull request #2857
from github/nickfyson/address-vulns9a45cd8
move use of input variables into env vars