From 75800b319391b1a77c8c93fc09c7180b7823db89 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Tue, 29 Sep 2026 18:47:19 +0000 Subject: [PATCH] chore(deps): update non-major (github-actions) --- .github/workflows/ci-verify.yml | 16 ++++++++-------- .github/workflows/codeql.yml | 6 +++--- .github/workflows/desktop-release.yml | 10 +++++----- .github/workflows/publish.yml | 2 +- .github/workflows/quality-ruleset-drift.yml | 2 +- .github/workflows/release-assets.yml | 2 +- .github/workflows/sbom.yml | 6 +++--- .github/workflows/security-actions.yml | 12 ++++++------ .github/workflows/security-dast.yml | 2 +- .github/workflows/security-scorecard.yml | 4 ++-- 10 files changed, 31 insertions(+), 31 deletions(-) diff --git a/.github/workflows/ci-verify.yml b/.github/workflows/ci-verify.yml index dc282205..7f22f2c8 100644 --- a/.github/workflows/ci-verify.yml +++ b/.github/workflows/ci-verify.yml @@ -42,7 +42,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block # This job only checks out the repo and runs local node --test files; @@ -71,7 +71,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block # checkout + npm ci, plus the full suite's own live calls: job-link-checker's @@ -157,7 +157,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block # checkout + npm ci + npm run build; observed on run 32512881196 @@ -243,7 +243,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block # checkout + npm ci + npm run build (apps/website, apps/docs); observed @@ -325,7 +325,7 @@ jobs: runs-on: windows-latest steps: - name: Harden the runner (audit Electron and Chromium downloads) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: audit - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -428,7 +428,7 @@ jobs: CAREERRAT_LIVE_BROWSER: "1" steps: - name: Harden the runner (audit Chromium and system dependency downloads) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: audit - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -533,7 +533,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block # Qlty pulls its own binary plus the Python/Go/Node toolchains its @@ -592,7 +592,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block # checkout + npm ci + npx knip; observed on run 32512881196 (Stable diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 3eadda81..93646ddc 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -33,7 +33,7 @@ jobs: language: [javascript-typescript] steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block # checkout, CodeQL bundle download (release-assets.githubusercontent.com @@ -49,10 +49,10 @@ jobs: with: persist-credentials: false - name: Initialize CodeQL - uses: github/codeql-action/init@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7 + uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 with: languages: ${{ matrix.language }} - name: Perform CodeQL analysis - uses: github/codeql-action/analyze@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7 + uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 with: category: "/language:${{ matrix.language }}" diff --git a/.github/workflows/desktop-release.yml b/.github/workflows/desktop-release.yml index 480a0837..1ed2d35e 100644 --- a/.github/workflows/desktop-release.yml +++ b/.github/workflows/desktop-release.yml @@ -52,7 +52,7 @@ jobs: tag: ${{ steps.resolve.outputs.tag }} steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block # This job only calls `gh api repos/.../tags` (dispatch path) and @@ -124,7 +124,7 @@ jobs: REPO: ${{ github.repository }} steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block allowed-endpoints: > @@ -208,7 +208,7 @@ jobs: TAG: ${{ needs.resolve-tag.outputs.tag }} steps: - name: Harden the runner (audit all outbound calls) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: # Stays on audit: this job's notarytool/stapler calls hit # Apple/Akamai/S3 hosts (appstoreconnect.apple.com, @@ -366,7 +366,7 @@ jobs: REPO: ${{ github.repository }} steps: - name: Harden the runner (audit dependency, browser, and signing endpoints) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: audit - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -498,7 +498,7 @@ jobs: WINDOWS_PUBLISHED: ${{ needs.build-windows-upload.outputs.published }} steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block # Release lookup/publication plus workflow dispatch and child-run diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 6fe0a645..38546b5a 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -45,7 +45,7 @@ jobs: REF_NAME: ${{ github.ref_name }} steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block # checkout, exact-release/feed verification, dependency install, and diff --git a/.github/workflows/quality-ruleset-drift.yml b/.github/workflows/quality-ruleset-drift.yml index d1ade560..11849bc5 100644 --- a/.github/workflows/quality-ruleset-drift.yml +++ b/.github/workflows/quality-ruleset-drift.yml @@ -57,7 +57,7 @@ jobs: contents: read # rulesets are world-readable on a public repo; see the header note steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block # checkout plus `gh api repos/.../rulesets` (both verify scripts). diff --git a/.github/workflows/release-assets.yml b/.github/workflows/release-assets.yml index 8c184bb2..021b6f94 100644 --- a/.github/workflows/release-assets.yml +++ b/.github/workflows/release-assets.yml @@ -36,7 +36,7 @@ jobs: REF_NAME: ${{ github.ref_name }} steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block # checkout plus `gh release view`. Observed on run 32488752322 diff --git a/.github/workflows/sbom.yml b/.github/workflows/sbom.yml index 520f92da..00ab6171 100644 --- a/.github/workflows/sbom.yml +++ b/.github/workflows/sbom.yml @@ -59,7 +59,7 @@ jobs: version: ${{ steps.resolve.outputs.version }} steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block # This job only calls `gh api repos/.../releases`, the same @@ -127,7 +127,7 @@ jobs: REPO: ${{ github.repository }} steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block # Observed from the v0.12.0 run (StepSecurity insights, run @@ -157,7 +157,7 @@ jobs: - name: Install dependencies run: npm ci - name: Generate the SPDX SBOM - uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 + uses: anchore/sbom-action@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2 with: path: . format: spdx-json diff --git a/.github/workflows/security-actions.yml b/.github/workflows/security-actions.yml index 93cb9a32..69c4b199 100644 --- a/.github/workflows/security-actions.yml +++ b/.github/workflows/security-actions.yml @@ -27,7 +27,7 @@ jobs: contents: read steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block # raven-actions/actionlint installs actionlint via a Python/pip helper @@ -56,7 +56,7 @@ jobs: contents: read steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block # astral-sh/setup-uv fetches uv from its GitHub release @@ -74,11 +74,11 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 + - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 with: # Pin the last mirror-verified release instead of racing a newly # published `latest` before its Astral mirror asset is available. - version: "0.12.5" + version: "0.12.15" - name: Scan workflows for Actions security anti-patterns run: uvx zizmor==1.29.0 .github/workflows/ --min-severity medium @@ -97,7 +97,7 @@ jobs: GITLEAKS_LINUX_X64_SHA256: "551f6fc83ea457d62a0d98237cbad105af8d557003051f41f3e7ca7b3f2470eb" steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block # checkout plus the pinned-and-hash-verified gitleaks tarball download @@ -129,7 +129,7 @@ jobs: contents: read steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block # actions/dependency-review-action calls the GitHub dependency-graph diff --git a/.github/workflows/security-dast.yml b/.github/workflows/security-dast.yml index da30eaf5..6d7960a2 100644 --- a/.github/workflows/security-dast.yml +++ b/.github/workflows/security-dast.yml @@ -26,7 +26,7 @@ jobs: permissions: {} steps: - name: Harden the runner (audit all outbound calls) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: # Stays on audit: the ZAP baseline scan spiders the live # careerrat.com production site and follows whatever it links to diff --git a/.github/workflows/security-scorecard.yml b/.github/workflows/security-scorecard.yml index b319b5dd..78e35e43 100644 --- a/.github/workflows/security-scorecard.yml +++ b/.github/workflows/security-scorecard.yml @@ -26,7 +26,7 @@ jobs: actions: read steps: - name: Harden the runner (block all outbound calls except the allowlist) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: block # ossf/scorecard-action's own dependencies: it checks OSS-Fuzz @@ -62,6 +62,6 @@ jobs: results_format: sarif publish_results: true - name: Upload SARIF results to code scanning - uses: github/codeql-action/upload-sarif@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7 + uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 with: sarif_file: results.sarif