Skip to content

fix: update harden-runner action to v2.16.0 due to security issue#435

Merged
zkoppert merged 1 commit intomainfrom
jm_update_harden_runner
Mar 19, 2026
Merged

fix: update harden-runner action to v2.16.0 due to security issue#435
zkoppert merged 1 commit intomainfrom
jm_update_harden_runner

Conversation

@jmeridth
Copy link
Collaborator

Pull Request

Proposed Changes

Readiness Checklist

Author/Contributor

  • If documentation is needed for this change, has that been included in this pull request
  • run make lint and fix any issues that you have introduced
  • run make test and ensure you have test coverage for the lines you are introducing

Signed-off-by: jmeridth <jmeridth@gmail.com>
@jmeridth jmeridth self-assigned this Mar 19, 2026
@jmeridth jmeridth requested a review from zkoppert as a code owner March 19, 2026 01:10
Copilot AI review requested due to automatic review settings March 19, 2026 01:10
@github-actions github-actions bot added the fix label Mar 19, 2026
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the pinned step-security/harden-runner GitHub Action used across CI workflows to address a security issue by moving from v2.15.1 to v2.16.0.

Changes:

  • Bump step-security/harden-runner from v2.15.1 to v2.16.0 (pinned by commit SHA) across all workflows that use it.
  • Keep the inline version comments in sync with the new pin.

Reviewed changes

Copilot reviewed 10 out of 10 changed files in this pull request and generated no comments.

Show a summary per file
File Description
.github/workflows/super-linter.yaml Update harden-runner pin to v2.16.0 for lint workflow.
.github/workflows/stale.yml Update harden-runner pin to v2.16.0 for stale workflow.
.github/workflows/scorecard.yml Update harden-runner pin to v2.16.0 for scorecard workflow.
.github/workflows/python-ci.yml Update harden-runner pin to v2.16.0 for Python CI matrix workflow.
.github/workflows/mark-ready-when-ready.yml Update harden-runner pin to v2.16.0 for PR readiness workflow.
.github/workflows/docker-ci.yml Update harden-runner pin to v2.16.0 for Docker CI workflow.
.github/workflows/dependency-review.yml Update harden-runner pin to v2.16.0 for dependency review workflow.
.github/workflows/copilot-setup-steps.yml Update harden-runner pin to v2.16.0 for Copilot setup workflow.
.github/workflows/contributors_report.yaml Update harden-runner pin to v2.16.0 for monthly contributors report workflow.
.github/workflows/codeql.yml Update harden-runner pin to v2.16.0 for CodeQL workflow.

@zkoppert zkoppert merged commit e3b0091 into main Mar 19, 2026
42 checks passed
@zkoppert zkoppert deleted the jm_update_harden_runner branch March 19, 2026 03:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants