Skip to content

fix(deps): update all non-major dependencies#319

Open
renovate-coveooss[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

fix(deps): update all non-major dependencies#319
renovate-coveooss[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate-coveooss

@renovate-coveooss renovate-coveooss Bot commented May 11, 2026

Copy link
Copy Markdown
Contributor

Jira: DT-4929

This PR contains the following updates:

Package Type Update Change Pending Age Adoption Passing Confidence
actions/checkout action patch v6.0.2v6.0.3 v6.1.0 age adoption passing confidence
actions/setup-go action minor v6.4.0v6.5.0 age adoption passing confidence
go (source) toolchain patch 1.26.21.26.5 age adoption passing confidence
golang.org/x/term require minor v0.42.0v0.45.0 age adoption passing confidence
golang.org/x/text require minor v0.36.0v0.40.0 age adoption passing confidence
step-security/harden-runner action minor v2.19.0v2.20.0 age adoption passing confidence

[skip release]


Release Notes

actions/checkout (actions/checkout)

v6.0.3

Compare Source

actions/setup-go (actions/setup-go)

v6.5.0

Compare Source

What's Changed

Dependency update

New Contributors

Full Changelog: actions/setup-go@v6...v6.5.0

step-security/harden-runner (step-security/harden-runner)

v2.20.0

Compare Source

What's Changed

  • Support for block policy for MacOS and Windows GitHub-hosted runners
  • Support for Bitrise MacOS GitHub Actions runners
  • HTTPS monitoring support for Bun for Linux runners (enterprise tier)

Full Changelog: step-security/harden-runner@v2.19.4...v2.20.0

v2.19.4

Compare Source

What's Changed

  • Improvements for HTTPS Monitoring for the Enterprise tier of Harden Runner

Full Changelog: step-security/harden-runner@v2.19.3...v2.19.4

v2.19.3

Compare Source

What's Changed

Full Changelog: step-security/harden-runner@v2.19.2...v2.19.3

v2.19.2

Compare Source

What's Changed

  • Update the Harden Runner agent for enterprise tier to use go 1.26 and fix minor bugs.

Full Changelog: step-security/harden-runner@v2.19.1...v2.19.2

v2.19.1

Compare Source

What's Changed

What the fix changes

  • Harden-Runner will detect ubuntu-slim runners and exit cleanly with an informational log message, instead of post harden runner step failing on chown: invalid user: 'undefined'.

What the fix does not do

  • Jobs running on ubuntu-slim will not be monitored by Harden-Runner. The agent relies on kernel-level features (that require elevated capabilities).
  • Per GitHub's docs on single-CPU runners: "The container for ubuntu-slim runners runs in unprivileged mode. This means that some operations requiring elevated privileges such as mounting file systems, using Docker-in-Docker, or accessing low-level kernel features are not supported." Those low-level kernel features are what the agent needs, so monitoring inside the unprivileged container is not feasible today.

For StepSecurity enterprise customers
If your security posture requires that workflows are always monitored, you can block the use of ubuntu-slim via workflow run policies see the Runner Label Policy docs. This lets you enforce that jobs only run on monitored runner types.

New Contributors

Full Changelog: step-security/harden-runner@v2.19.0...v2.19.1


Configuration

📅 Schedule: (in timezone America/Toronto)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • "after 9:00am and before 12:00pm on tuesday, wednesday, thursday"

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@svcsnykcoveo

svcsnykcoveo commented May 11, 2026

Copy link
Copy Markdown

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@renovate-coveooss
renovate-coveooss Bot force-pushed the renovate/all-minor-patch branch from 51bf667 to 23f1881 Compare May 15, 2026 14:44
@renovate-coveooss renovate-coveooss Bot changed the title chore(deps): update step-security/harden-runner action to v2.19.1 chore(deps): update all non-major dependencies May 15, 2026
@renovate-coveooss
renovate-coveooss Bot force-pushed the renovate/all-minor-patch branch from 23f1881 to 717d188 Compare May 15, 2026 15:05
@renovate-coveooss renovate-coveooss Bot changed the title chore(deps): update all non-major dependencies fix(deps): update all non-major dependencies May 15, 2026
@renovate-coveooss

renovate-coveooss Bot commented May 15, 2026

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated

Details:

Package Change
golang.org/x/sys v0.43.0 -> v0.47.0

@renovate-coveooss
renovate-coveooss Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from fffbb92 to 57c95fb Compare May 21, 2026 21:42
@renovate-coveooss
renovate-coveooss Bot force-pushed the renovate/all-minor-patch branch from 57c95fb to 484ac41 Compare May 28, 2026 16:14
@renovate-coveooss
renovate-coveooss Bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from 121d631 to 236c6e9 Compare June 15, 2026 16:02
@renovate-coveooss
renovate-coveooss Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 69f6fc7 to 33756b4 Compare July 7, 2026 21:14
@renovate-coveooss
renovate-coveooss Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 729b64f to 4c95daf Compare July 14, 2026 10:15
@renovate-coveooss
renovate-coveooss Bot force-pushed the renovate/all-minor-patch branch from 4c95daf to 92e748b Compare July 15, 2026 15:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant