Skip to content

chore(deps): update all non-major dependencies#670

Merged
renovate[bot] merged 1 commit intomainfrom
renovate/all-minor-patch
Mar 17, 2026
Merged

chore(deps): update all non-major dependencies#670
renovate[bot] merged 1 commit intomainfrom
renovate/all-minor-patch

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Mar 15, 2026

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
caniuse-lite 1.0.300017771.0.30001778 age confidence dependencies patch 1.0.30001779
step-security/harden-runner v2.15.1v2.16.0 age confidence action minor

Release Notes

browserslist/caniuse-lite (caniuse-lite)

v1.0.30001778

Compare Source

step-security/harden-runner (step-security/harden-runner)

v2.16.0

Compare Source

What's Changed
  • Updated action.yml to use node24
  • Security fix: Fixed a medium severity vulnerability where the egress block policy could be bypassed via DNS over HTTPS (DoH) by proxying DNS queries through a permitted resolver, allowing data exfiltration even with a restrictive allowed-endpoints list. This issue only affects the Community Tier; the Enterprise Tier is not affected. See GHSA-46g3-37rh-v698 for details.
  • Security fix: Fixed a medium severity vulnerability where the egress block policy could be bypassed via DNS queries over TCP to external resolvers, allowing outbound network communication that evades configured network restrictions. This issue only affects the Community Tier; the Enterprise Tier is not affected. See GHSA-g699-3x6g-wm3g for details.

Full Changelog: step-security/harden-runner@v2.15.1...v2.16.0


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot enabled auto-merge March 15, 2026 05:26
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 4d17e57 to a945251 Compare March 16, 2026 09:51
@renovate renovate bot changed the title chore(deps): update dependency caniuse-lite to v1.0.30001778 chore(deps): update all non-major dependencies Mar 16, 2026
@renovate renovate bot added this pull request to the merge queue Mar 17, 2026
Merged via the queue into main with commit 3db7038 Mar 17, 2026
3 checks passed
@renovate renovate bot deleted the renovate/all-minor-patch branch March 17, 2026 00:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant