Sourced from step-security/harden-runner's releases.
v2.10.1
What's Changed
Release v2.10.1 by
@varunsh-coder
in step-security/harden-runner#463 Bug fix: Resolves an issue where DNS resolution of .local domains was failing when using a Kind cluster in a GitHub Actions workflow.Full Changelog: https://github.com/step-security/harden-runner/compare/v2...v2.10.1
v2.10.0
What's Changed
Release v2.10.0 by
@h0x0er
and@varunsh-coder
in step-security/harden-runner#455ARM Support: Harden-Runner Enterprise tier now supports GitHub-hosted ARM runners. This includes all the features that apply to previously supported GitHub-hosted x64 Linux runners.
Full Changelog: https://github.com/step-security/harden-runner/compare/v2...v2.10.0
v2.9.1
What's Changed
Release v2.9.1 by
@h0x0er
and@varunsh-coder
in #440 This release includes two changes:
- Updated markdown displayed in the job summary by the Harden-Runner Action.
- Fixed a bug affecting Enterprise Tier customers where the agent attempted to upload telemetry for jobs with disable-telemetry set to true. No telemetry was uploaded as the endpoint was not in the allowed list.
Full Changelog: https://github.com/step-security/harden-runner/compare/v2...v2.9.1
v2.9.0
What's Changed
Release v2.9.0 by
@h0x0er
and@varunsh-coder
in step-security/harden-runner#435 This release includes:
- Enterprise Tier - Telemetry Upload Enhancement: For the enterprise tier, this change helps overcome size constraints, allowing for more reliable telemetry uploads from the Harden-Runner agent to the StepSecurity backend API. No configuration change is needed to enable this.
- Harden-Runner Agent Authentication: The Harden-Runner agent now uses a per-job key to authenticate to the StepSecurity backend API to submit telemetry. This change prevents the submission of telemetry data anonymously for a given job, improving the integrity of the data collection process. No configuration change is needed to enable this.
- README Update: A Table of Contents has been added to the README file to improve navigation. This makes it easier for users to find the information they need quickly.
- Dependency Update: Updated the
braces
npm package dependency to a non-vulnerable version. The vulnerability inbraces
did not affect the Harden Runner ActionFull Changelog: https://github.com/step-security/harden-runner/compare/v2...v2.9.0
91182cc
Merge pull request #463
from step-security/rc-1459ec1c6
Update agent1d23703
Merge pull request #461
from step-security/varunsh-coder-patch-1b03bdda
Update README.md3d8dd68
Update README.md446798f
Merge pull request #455
from step-security/rc-12f0d3b1e
Update agentb7880a2
update distdade49e
Merge pull request #456
from h0x0er/arm-supportd6248be
bump enterprise agent version