- 
                Notifications
    You must be signed in to change notification settings 
- Fork 76
Pull requests: step-security/harden-runner
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
      Bump github/codeql-action from 3.25.13 to 4.31.2
        
              
                dependencies
  Pull requests that update a dependency file 
              
                github_actions
  Pull requests that update GitHub Actions code 
        
      
    
      
  
        
          #605
            opened Oct 30, 2025  by
            dependabot
            bot
        
        
            
    
  
    Loading…
 
        
        
      
    
      Bump step-security/publish-unit-test-result-action from 2.20.0 to 2.20.5
        
              
                dependencies
  Pull requests that update a dependency file 
              
                github_actions
  Pull requests that update GitHub Actions code 
        
      
    
      
  
        
          #602
            opened Oct 23, 2025  by
            dependabot
            bot
        
        
            
    
  
    Loading…
 
        
        
      
    
      Bump actions/dependency-review-action from 4.3.2 to 4.8.1
        
              
                dependencies
  Pull requests that update a dependency file 
              
                github_actions
  Pull requests that update GitHub Actions code 
        
      
    
      
  
        
          #600
            opened Oct 10, 2025  by
            dependabot
            bot
        
        
            
    
  
    Loading…
 
        
        
      
    
      Bump ossf/scorecard-action from 2.4.0 to 2.4.3
        
              
                dependencies
  Pull requests that update a dependency file 
              
                github_actions
  Pull requests that update GitHub Actions code 
        
      
    
      
  
        
          #596
            opened Sep 30, 2025  by
            dependabot
            bot
        
        
            
    
  
    Loading…
 
        
        
      
    
      Bump codecov/codecov-action from 3.1.4 to 5.5.1
        
              
                dependencies
  Pull requests that update a dependency file 
              
                github_actions
  Pull requests that update GitHub Actions code 
        
      
    
      
  
        
          #586
            opened Sep 4, 2025  by
            dependabot
            bot
        
        
            
    
  
    Loading…
 
        
        
      
    
      Bump actions/checkout from 3 to 5
        
              
                dependencies
  Pull requests that update a dependency file 
              
                github_actions
  Pull requests that update GitHub Actions code 
        
      
    
      
  
        
          #576
            opened Aug 12, 2025  by
            dependabot
            bot
        
        
            
    
  
    Loading…
 
        
        
      
    
      Bump form-data from 2.5.1 to 2.5.5
        
              
                dependencies
  Pull requests that update a dependency file 
              
                javascript
  Pull requests that update Javascript code 
        
      
    
      
  
        
          #568
            opened Jul 22, 2025  by
            dependabot
            bot
        
        
            
    
  
    Loading…
 
        
        
      
    
      Bump brace-expansion from 1.1.11 to 1.1.12
        
              
                dependencies
  Pull requests that update a dependency file 
              
                javascript
  Pull requests that update Javascript code 
        
      
    
      
  
        
          #557
            opened Jun 12, 2025  by
            dependabot
            bot
        
        
            
    
  
    Loading…
 
        
        
      
    
      Bump @octokit/request and @actions/github
        
              
                dependencies
  Pull requests that update a dependency file 
              
                javascript
  Pull requests that update Javascript code 
        
      
    
      
  
        
          #531
            opened Apr 1, 2025  by
            dependabot
            bot
        
        
            
    
  
    Loading…
 
        
        
      
    
      [StepSecurity] Apply security best practices
      
    
      
  
        
          #528
            opened Mar 25, 2025  by
            stepsecurity-app
            bot
        
        
            
    
  
    Loading…
 
        
        
      
    
      Bump @octokit/plugin-paginate-rest and @actions/github
        
              
                dependencies
  Pull requests that update a dependency file 
              
                javascript
  Pull requests that update Javascript code 
        
      
    
      
  
        
          #502
            opened Feb 18, 2025  by
            dependabot
            bot
        
        
            
    
  
    Loading…
 
        
        
      
    
      Bump @octokit/request-error and @actions/github
        
              
                dependencies
  Pull requests that update a dependency file 
              
                javascript
  Pull requests that update Javascript code 
        
      
    
      
  
        
          #501
            opened Feb 18, 2025  by
            dependabot
            bot
        
        
            
    
  
    Loading…
 
        
        
      
    
      Bump step-security/harden-runner from 2.9.1 to 2.10.0
        
              
                dependencies
  Pull requests that update a dependency file 
              
                github_actions
  Pull requests that update GitHub Actions code 
        
      
    
      
  
        
          #462
            opened Sep 10, 2024  by
            dependabot
            bot
        
        
            
    
  
    Loading…
 
        
        
      
    
      Bump actions/upload-artifact from 4.3.4 to 4.4.0
        
              
                dependencies
  Pull requests that update a dependency file 
              
                github_actions
  Pull requests that update GitHub Actions code 
        
      
    
      
  
        
          #460
            opened Aug 30, 2024  by
            dependabot
            bot
        
        
            
    
  
    Loading…
 
        
        
      
    
      Bump braces from 3.0.2 to 3.0.3
        
              
                dependencies
  Pull requests that update a dependency file 
              
                javascript
  Pull requests that update Javascript code 
        
      
    
        
          #430
            opened Jun 13, 2024  by
            dependabot
            bot
        
        
            
    
  
    Loading…
 
        
        
      
    
  
  ProTip!
  Type g i on any issue or pull request to go back to the issue listing page.