Skip to content

build(deps): bump step-security/harden-runner from 2.16.0 to 2.16.1#1490

Merged
pethers merged 2 commits intomainfrom
dependabot/github_actions/step-security/harden-runner-2.16.1
Mar 31, 2026
Merged

build(deps): bump step-security/harden-runner from 2.16.0 to 2.16.1#1490
pethers merged 2 commits intomainfrom
dependabot/github_actions/step-security/harden-runner-2.16.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 31, 2026

Bumps step-security/harden-runner from 2.16.0 to 2.16.1.

Release notes

Sourced from step-security/harden-runner's releases.

v2.16.1

What's Changed

Enterprise tier: Added support for direct IP addresses in the allow list Community tier: Migrated Harden Runner telemetry to a new endpoint

Full Changelog: step-security/harden-runner@v2.16.0...v2.16.1

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.16.0 to 2.16.1.
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](step-security/harden-runner@fa2e9d6...fe10465)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-version: 2.16.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot bot commented on behalf of github Mar 31, 2026

Labels

The following labels could not be found: github-actions. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot bot added the dependencies Dependency updates label Mar 31, 2026
Copilot AI review requested due to automatic review settings March 31, 2026 19:52
@dependabot dependabot bot added the dependencies Dependency updates label Mar 31, 2026
@dependabot dependabot bot review requested due to automatic review settings March 31, 2026 19:52
@github-actions github-actions bot added cia-data CIA platform data integration security Security improvements workflow GitHub Actions workflows data-pipeline ETL and data processing schema Data schema changes translation Translation updates ci-cd CI/CD pipeline changes deployment Deployment configuration performance Performance optimization monitoring Monitoring and alerting testing Test coverage accessibility WCAG 2.1 AA compliance agentic-workflow Agentic workflow changes size-m Medium change (50-250 lines) labels Mar 31, 2026
@github-actions
Copy link
Copy Markdown
Contributor

🏷️ Automatic Labeling Summary

This PR has been automatically labeled based on the files changed and PR metadata.

Applied Labels: dependencies,cia-data,security,workflow,data-pipeline,schema,translation,ci-cd,deployment,performance,monitoring,testing,accessibility,size-m,agentic-workflow

Label Categories

  • 🗳️ Content: news, dashboard, visualization, intelligence
  • 💻 Technology: html-css, javascript, workflow, security
  • 📊 Data: cia-data, riksdag-data, data-pipeline, schema
  • 🌍 I18n: i18n, translation, rtl
  • 🔒 ISMS: isms, iso-27001, nist-csf, cis-controls
  • 🏗️ Infrastructure: ci-cd, deployment, performance, monitoring
  • 🔄 Quality: testing, accessibility, documentation, refactor
  • 🤖 AI: agent, skill, agentic-workflow

For more information, see .github/labeler.yml.

@github-actions
Copy link
Copy Markdown
Contributor

🔍 Lighthouse Performance Audit

Category Score Status
Performance 85/100 🟡
Accessibility 95/100 🟢
Best Practices 90/100 🟢
SEO 95/100 🟢

📥 Download full Lighthouse report

Budget Compliance: Performance budgets enforced via budget.json

Copilot AI review requested due to automatic review settings March 31, 2026 20:04
@github-actions
Copy link
Copy Markdown
Contributor

🔍 Lighthouse Performance Audit

Category Score Status
Performance 85/100 🟡
Accessibility 95/100 🟢
Best Practices 90/100 🟢
SEO 95/100 🟢

📥 Download full Lighthouse report

Budget Compliance: Performance budgets enforced via budget.json

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the pinned GitHub Action reference for step-security/harden-runner across the repository’s GitHub Actions workflows, moving from v2.16.0 to v2.16.1 (by commit SHA) to keep runner-hardening behavior current and consistently pinned.

Changes:

  • Bump step-security/harden-runner from v2.16.0 to v2.16.1 across all workflows that use it.
  • Update the pinned commit SHA and inline version comment in each affected workflow.

Reviewed changes

Copilot reviewed 22 out of 22 changed files in this pull request and generated no comments.

Show a summary per file
File Description
.github/workflows/validate-cia-data.yml Bumps harden-runner pin to v2.16.1.
.github/workflows/uptime-monitor.yml Bumps harden-runner pin to v2.16.1.
.github/workflows/update-cia-stats.yml Bumps harden-runner pin to v2.16.1.
.github/workflows/translation-validation.yml Bumps harden-runner pin to v2.16.1.
.github/workflows/test-news.yml Bumps harden-runner pin to v2.16.1 (both jobs).
.github/workflows/test-homepage.yml Bumps harden-runner pin to v2.16.1 (both jobs).
.github/workflows/test-dashboard.yml Bumps harden-runner pin to v2.16.1 (both jobs).
.github/workflows/sync-cia-schemas.yml Bumps harden-runner pin to v2.16.1.
.github/workflows/setup-labels.yml Bumps harden-runner pin to v2.16.1.
.github/workflows/scorecards.yml Bumps harden-runner pin to v2.16.1.
.github/workflows/release.yml Bumps harden-runner pin to v2.16.1 (all occurrences).
.github/workflows/quality-checks.yml Bumps harden-runner pin to v2.16.1 (all jobs/occurrences).
.github/workflows/lighthouse-ci.yml Bumps harden-runner pin to v2.16.1.
.github/workflows/labeler.yml Bumps harden-runner pin to v2.16.1.
.github/workflows/jsdoc-validation.yml Bumps harden-runner pin to v2.16.1.
.github/workflows/javascript-testing.yml Bumps harden-runner pin to v2.16.1 (all jobs/occurrences).
.github/workflows/deploy-s3.yml Bumps harden-runner pin to v2.16.1.
.github/workflows/dependency-review.yml Bumps harden-runner pin to v2.16.1.
.github/workflows/data-pipeline.yml Bumps harden-runner pin to v2.16.1.
.github/workflows/compile-agentic-workflows.yml Bumps harden-runner pin to v2.16.1.
.github/workflows/codeql.yml Bumps harden-runner pin to v2.16.1.
.github/workflows/check-cia-schema-updates.yml Bumps harden-runner pin to v2.16.1.

@pethers pethers merged commit 314f08e into main Mar 31, 2026
17 checks passed
@pethers pethers deleted the dependabot/github_actions/step-security/harden-runner-2.16.1 branch March 31, 2026 20:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

accessibility WCAG 2.1 AA compliance agentic-workflow Agentic workflow changes ci-cd CI/CD pipeline changes cia-data CIA platform data integration data-pipeline ETL and data processing dependencies Dependency updates deployment Deployment configuration monitoring Monitoring and alerting performance Performance optimization schema Data schema changes security Security improvements size-m Medium change (50-250 lines) testing Test coverage translation Translation updates workflow GitHub Actions workflows

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants