Skip to content

chore(deps): update github actions#2370

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/github-actions
Open

chore(deps): update github actions#2370
renovate[bot] wants to merge 1 commit intomainfrom
renovate/github-actions

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Feb 20, 2026

This PR contains the following updates:

Package Type Update Change
backstage/actions action patch v0.7.6v0.7.8
step-security/harden-runner action minor v2.14.1v2.15.0
step-security/harden-runner action minor v2.14.2v2.15.0
tombi-toml/setup-tombi action patch v1.0.7v1.0.8

Release Notes

backstage/actions (backstage/actions)

v0.7.8

Compare Source

What's Changed

  • Add exponential backoff retry for transient network errors in Octokit client by @​Copilot in #​182

New Contributors

Full Changelog: backstage/actions@v0.7.7...v0.7.8

v0.7.7

Compare Source

What's Changed

  • pr-automation: automatically assign maintainers for review by @​Rugvip in #​181

Full Changelog: backstage/actions@v0.7.6...v0.7.7

step-security/harden-runner (step-security/harden-runner)

v2.15.0

Compare Source

What's Changed

Windows and macOS runner support

We are excited to announce that Harden Runner now supports Windows and macOS runners, extending runtime security beyond Linux for the first time.

Insights for Windows and macOS runners will be displayed in the same consistent format you are already familiar with from Linux runners, giving you a unified view of runtime activity across all platforms.

Full Changelog: step-security/harden-runner@v2.14.2...v2.15.0

v2.14.2

Compare Source

What's Changed

Security fix: Fixed a medium severity vulnerability where outbound network connections using sendto, sendmsg, and sendmmsg socket system calls could bypass audit logging when using egress-policy: audit. This issue only affects the Community Tier in audit mode; block mode and Enterprise Tier were not affected. See GHSA-cpmj-h4f6-r6pq for details.

Full Changelog: step-security/harden-runner@v2.14.1...v2.14.2

tombi-toml/setup-tombi (tombi-toml/setup-tombi)

v1.0.8

Compare Source

What's Changed

Full Changelog: tombi-toml/setup-tombi@v1.0.7...v1.0.8


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from a team as a code owner February 20, 2026 17:40
@renovate renovate bot added the dependencies Pull requests that update a dependency file label Feb 20, 2026
@renovate renovate bot requested a review from a team as a code owner February 20, 2026 17:40
@renovate renovate bot force-pushed the renovate/github-actions branch from d82fffb to d6bdb8a Compare February 23, 2026 06:52
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate bot force-pushed the renovate/github-actions branch from d6bdb8a to 5e6d930 Compare March 1, 2026 14:14
@renovate renovate bot changed the title chore(deps): update backstage/actions action to v0.7.7 chore(deps): update github actions Mar 1, 2026
@sonarqubecloud
Copy link

sonarqubecloud bot commented Mar 1, 2026

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants