Skip to content

build(deps): bump ossf/scorecard-action from 55891bbd73f2425e97637d96e306fc9d491d0b21 to 2d1146689b8cda280b9bc96326124645441f03bc - #15

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/ossf/scorecard-action-2d1146689b8cda280b9bc96326124645441f03bc
Open

build(deps): bump ossf/scorecard-action from 55891bbd73f2425e97637d96e306fc9d491d0b21 to 2d1146689b8cda280b9bc96326124645441f03bc#15
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/ossf/scorecard-action-2d1146689b8cda280b9bc96326124645441f03bc

build(deps): bump ossf/scorecard-action

56e181a
Select commit
Loading
Failed to load commit list.
StepSecurity Actions Security / StepSecurity Harden-Runner succeeded Aug 14, 2026 in 1m 25s

No anomalous activity on CI/CD runners

No new Harden-Runner detections for this pull request.

Details

Harden-Runner monitors all outbound traffic from each job at the DNS and network layers to ensure that CI/CD runners do not communicate with unauthorized destinations.
This reduces the risk of CI/CD secrets and source code being exfiltrated.

📋 Monitored GitHub Actions workflow runs

The following GitHub Actions workflow runs were monitored as part of this pull request.

Workflow Run ID Unique Destinations Actions Used Detailed Insights
test.yml 31774048642 14 2 View Insights
auto_cherry_pick.yml 31774051270 - - Harden-Runner not enabled
claude_review.yml 31774051309 1 4 View Insights
dependency-review.yml 31774051023 3 3 View Insights
codeql.yml 31774051033 2 3 View Insights

📚 Learn More

You can learn more about this GitHub check here