Skip to content

Bump yaml from 2.7.0 to 2.8.0#69

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/yaml-2.8.0
Closed

Bump yaml from 2.7.0 to 2.8.0#69
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/yaml-2.8.0

Bump yaml from 2.7.0 to 2.8.0

f7abe46
Select commit
Loading
Failed to load commit list.
This check has been archived and is scheduled for deletion. Learn more about checks retention
StepSecurity Actions Security / StepSecurity Harden-Runner succeeded May 20, 2025 in 30m 35s

No anomalous activity on CI/CD runners

No new Harden-Runner detections for this pull request.

Details

Harden-Runner monitors all outbound traffic from each job at the DNS and network layers to ensure that CI/CD runners do not communicate with unauthorized destinations.
This reduces the risk of CI/CD secrets and source code being exfiltrated.

📋 Monitored GitHub Actions workflow runs

The following GitHub Actions workflow runs were monitored as part of this pull request.

Workflow Run ID Unique Destinations Actions Used Detailed Insights
test.yml 16773869981 2 3 View Insights
test.yml 15675842646 2 3 View Insights
multi-job-example.yml 15131023362 2 2 View Insights
guarddog.yml 15131023421 - - Harden-Runner not enabled
codeql.yml 15131023372 3 3 View Insights
test.yml 15131022810 2 3 View Insights
matrix-example.yml 15131023343 1 2 View Insights
multi-job-example.yml 15131022801 1 2 View Insights
test.yml 15131023377 1 3 View Insights
dependency-review.yml 15131023353 3 3 View Insights

📚 Learn More

You can learn more about this GitHub check here