Skip to content

build(deps): bump the all group across 1 directory with 5 updates - #476

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/all-ac97f980d0
Open

build(deps): bump the all group across 1 directory with 5 updates#476
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/all-ac97f980d0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 2, 2026

Copy link
Copy Markdown
Contributor

Bumps the all group with 5 updates in the / directory:

Package From To
step-security/harden-runner 2.20.0 2.21.1
step-security/action-actionlint 1.72.0 1.73.1
chainguard-dev/actions/apt-faster 1.6.29 1.6.34
chainguard-dev/actions/setup-melange 1.6.29 1.6.34
zizmorcore/zizmor-action 0.6.2 0.6.3

Updates step-security/harden-runner from 2.20.0 to 2.21.1

Release notes

Sourced from step-security/harden-runner's releases.

v2.21.1

What's Changed

  • Improved performance of the disable-sudo feature.
  • Fixed an issue in the Community tier where new endpoints required by the GitHub Actions runner were not being implicitly allowed in block mode.
  • Fixed the Harden-Runner post step failing on Linux distributions that do not have a merged /usr filesystem layout (for example Debian 11), where /usr/bin/echo does not exist. This mainly affected self-hosted runners.
  • Documentation updates: clarified which features are in the Community (free) vs Enterprise tier.

Full Changelog: step-security/harden-runner@v2.21.0...v2.21.1

v2.21.0

What's Changed

  • Support for denied endpoints in block mode. This is included in the enterprise tier. Customers can deny outbound calls, for example, to public package registries.
  • Improved Support for AWS CodeBuild GitHub Actions Runners.
  • Bug fixes.

Full Changelog: step-security/harden-runner@v2.20.1...v2.21.0

v2.20.1

What's Changed

  • AWS CodeBuild-hosted runner support
  • Implicitly allow single-labeled (internal) domains in block-mode

Full Changelog: step-security/harden-runner@v2.20.0...v2.20.1

Commits
  • e14015d Merge pull request #690 from step-security/rc-43
  • 9001249 docs: update harden-runner version pin to v2.21.0 in getting started example
  • a447fba docs: expand enterprise feature list and document custom VM and ubuntu-slim l...
  • b0eaf8d docs: clarify community vs enterprise tiers and add maintained actions section
  • 063e8e3 Merge pull request #687 from rohan-stepsecurity/rp/fix/bin-echo-fallback
  • f46bdc1 chore: bump agent-ebpf to v1.9.1 and agent to v0.16.3
  • 42e6daa fix: fall back to /bin/echo for non-usr-merged distros
  • 05e3151 Merge pull request #684 from step-security/rc-42
  • 0f37afa fix: ignore denied-endpoints on non-enterprise tier
  • 93b58ee fix: resolve cache host read-first and never downgrade egress policy
  • Additional commits viewable in compare view

Updates step-security/action-actionlint from 1.72.0 to 1.73.1

Release notes

Sourced from step-security/action-actionlint's releases.

v1.73.1

What's Changed

New Contributors

Full Changelog: step-security/action-actionlint@v1.72.0...v1.73.1

Commits
  • b90a9dd Merge pull request #54 from step-security/Raj-StepSecurity-patch-8
  • 310ceb1 feat: updated docker image
  • 5938d40 Merge pull request #53 from step-security/fix/missed-jq-added
  • 1b1230a fix: missed jq added back
  • 7fd6cc8 Merge pull request #51 from step-security/Raj-StepSecurity-patch-6
  • 98405ee feat: Update action.yml with latest docker image
  • 498cea3 Merge pull request #50 from step-security/auto-cherry-pick
  • 4b4ce07 comments addressed
  • f88d567 conflicted commits cherry-picked
  • 6b6250f feat: add shellcheck installation script and integrate into Dockerfile and ac...
  • Additional commits viewable in compare view

Updates chainguard-dev/actions/apt-faster from 1.6.29 to 1.6.34

Release notes

Sourced from chainguard-dev/actions/apt-faster's releases.

v1.6.34

What's Changed

Full Changelog: chainguard-dev/actions@v1.6.33...v1.6.34

v1.6.33

What's Changed

New Contributors

Full Changelog: chainguard-dev/actions@v1.6.32...v1.6.33

v1.6.32

What's Changed

Full Changelog: chainguard-dev/actions@v1.6.31...v1.6.32

v1.6.31

What's Changed

Full Changelog: chainguard-dev/actions@v1.6.30...v1.6.31

v1.6.30

What's Changed

New Contributors

Full Changelog: chainguard-dev/actions@v1.6.29...v1.6.30

Commits
  • a9d4aa7 fix(melange-build-pkg): fix --source-dir (#991)
  • 0ffab11 fix(melange-build-pkg): respect workdir when running chown (#990)
  • 76c93da feat(melange-build): add source-dir input (#989)
  • 7bd1e94 build(deps-dev): bump eslint from 9.39.4 to 10.8.0 in /otel-export (#1015)
  • 70ea519 build(deps): bump the actions group across 8 directories with 6 updates (#1024)
  • bed8050 build(deps): bump the actions group across 1 directory with 5 updates (#1023)
  • 9d63165 build(deps): bump the actions group across 8 directories with 8 updates (#1018)
  • 06277e4 build(deps): bump reviewdog/action-actionlint from 1.72.0 to 1.73.0 (#1019)
  • fed81b5 build(deps): bump otel-export dependencies and rebuild dist (#1012)
  • 050eb20 build(deps): bump step-security/harden-runner from 2.19.4 to 2.20.0 (#993)
  • Additional commits viewable in compare view

Updates chainguard-dev/actions/setup-melange from 1.6.29 to 1.6.34

Release notes

Sourced from chainguard-dev/actions/setup-melange's releases.

v1.6.34

What's Changed

Full Changelog: chainguard-dev/actions@v1.6.33...v1.6.34

v1.6.33

What's Changed

New Contributors

Full Changelog: chainguard-dev/actions@v1.6.32...v1.6.33

v1.6.32

What's Changed

Full Changelog: chainguard-dev/actions@v1.6.31...v1.6.32

v1.6.31

What's Changed

Full Changelog: chainguard-dev/actions@v1.6.30...v1.6.31

v1.6.30

What's Changed

New Contributors

Full Changelog: chainguard-dev/actions@v1.6.29...v1.6.30

Commits
  • a9d4aa7 fix(melange-build-pkg): fix --source-dir (#991)
  • 0ffab11 fix(melange-build-pkg): respect workdir when running chown (#990)
  • 76c93da feat(melange-build): add source-dir input (#989)
  • 7bd1e94 build(deps-dev): bump eslint from 9.39.4 to 10.8.0 in /otel-export (#1015)
  • 70ea519 build(deps): bump the actions group across 8 directories with 6 updates (#1024)
  • bed8050 build(deps): bump the actions group across 1 directory with 5 updates (#1023)
  • 9d63165 build(deps): bump the actions group across 8 directories with 8 updates (#1018)
  • 06277e4 build(deps): bump reviewdog/action-actionlint from 1.72.0 to 1.73.0 (#1019)
  • fed81b5 build(deps): bump otel-export dependencies and rebuild dist (#1012)
  • 050eb20 build(deps): bump step-security/harden-runner from 2.19.4 to 2.20.0 (#993)
  • Additional commits viewable in compare view

Updates zizmorcore/zizmor-action from 0.6.2 to 0.6.3

Release notes

Sourced from zizmorcore/zizmor-action's releases.

v0.6.3

zizmor 1.30.0 is now the default version.

Release notes: zizmorcore/zizmor-action#1300

Commits
  • 70fb788 Sync zizmor versions (#162)
  • 7999d8c chore(deps): bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 in ...
  • 2ae1ce9 chore(deps): bump github/codeql-action/upload-sarif (#160)
  • 951a5ee Skip prerelease versions in sync-zizmor-versions workflow (#158)
  • 79f0191 chore(deps): bump github/codeql-action/upload-sarif (#156)
  • 26a3ae6 sync-zizmor-versions: retry up to 5 times (#155)
  • 435cb31 chore(deps): bump github/codeql-action/upload-sarif (#151)
  • d6cec10 Try the new self-referencing syntax (#148)
  • edd9b84 README: bump pins (#150)
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 2, 2026
Bumps the all group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.20.0` | `2.21.1` |
| [step-security/action-actionlint](https://github.com/step-security/action-actionlint) | `1.72.0` | `1.73.1` |
| [chainguard-dev/actions/apt-faster](https://github.com/chainguard-dev/actions) | `1.6.29` | `1.6.34` |
| [chainguard-dev/actions/setup-melange](https://github.com/chainguard-dev/actions) | `1.6.29` | `1.6.34` |
| [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) | `0.6.2` | `0.6.3` |



Updates `step-security/harden-runner` from 2.20.0 to 2.21.1
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](step-security/harden-runner@bf7454d...e14015d)

Updates `step-security/action-actionlint` from 1.72.0 to 1.73.1
- [Release notes](https://github.com/step-security/action-actionlint/releases)
- [Commits](step-security/action-actionlint@c3aa382...b90a9dd)

Updates `chainguard-dev/actions/apt-faster` from 1.6.29 to 1.6.34
- [Release notes](https://github.com/chainguard-dev/actions/releases)
- [Commits](chainguard-dev/actions@b2555de...a9d4aa7)

Updates `chainguard-dev/actions/setup-melange` from 1.6.29 to 1.6.34
- [Release notes](https://github.com/chainguard-dev/actions/releases)
- [Commits](chainguard-dev/actions@b2555de...a9d4aa7)

Updates `zizmorcore/zizmor-action` from 0.6.2 to 0.6.3
- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)
- [Commits](zizmorcore/zizmor-action@3dc1ecc...70fb788)

---
updated-dependencies:
- dependency-name: chainguard-dev/actions/apt-faster
  dependency-version: 1.6.33
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: chainguard-dev/actions/setup-melange
  dependency-version: 1.6.33
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: step-security/action-actionlint
  dependency-version: 1.73.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: step-security/harden-runner
  dependency-version: 2.21.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: zizmorcore/zizmor-action
  dependency-version: 0.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/all-ac97f980d0 branch from bfa934e to 404868b Compare September 9, 2026 13:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants