Skip to content

Bump step-security/harden-runner from 2.16.1 to 2.17.0#46

Merged
hsbt merged 1 commit intomasterfrom
dependabot/github_actions/step-security/harden-runner-2.17.0
Apr 14, 2026
Merged

Bump step-security/harden-runner from 2.16.1 to 2.17.0#46
hsbt merged 1 commit intomasterfrom
dependabot/github_actions/step-security/harden-runner-2.17.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Apr 13, 2026

Bumps step-security/harden-runner from 2.16.1 to 2.17.0.

Release notes

Sourced from step-security/harden-runner's releases.

v2.17.0

What's Changed

Policy Store Support

Added use-policy-store and api-key inputs to fetch security policies directly from the StepSecurity Policy Store. Policies can be defined and attached at the workflow, repo, org, or cluster (ARC) level, with the most granular policy taking precedence. This is the preferred method over the existing policy input which requires id-token: write permission. If no policy is found in the store, the action defaults to audit mode.

Full Changelog: step-security/harden-runner@v2.16.1...v2.17.0

Commits

@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Apr 13, 2026
@hsbt
Copy link
Copy Markdown
Member

hsbt commented Apr 14, 2026

@dependabot rebase

Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.16.1 to 2.17.0.
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](step-security/harden-runner@fe10465...f808768)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-version: 2.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/github_actions/step-security/harden-runner-2.17.0 branch from 0dbbf2d to b6539ce Compare April 14, 2026 03:58
@hsbt hsbt merged commit 7e8de2b into master Apr 14, 2026
44 checks passed
@hsbt hsbt deleted the dependabot/github_actions/step-security/harden-runner-2.17.0 branch April 14, 2026 04:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant