Skip to content

zarf/0.67.0-r0: cve remediation#75221

Closed
octo-sts[bot] wants to merge 1 commit into
mainfrom
cve-zarf-0.67.0-r0-2ff7cb511ef4e3f1bcb19e07da229457
Closed

zarf/0.67.0-r0: cve remediation#75221
octo-sts[bot] wants to merge 1 commit into
mainfrom
cve-zarf-0.67.0-r0-2ff7cb511ef4e3f1bcb19e07da229457

zarf/0.67.0-r0: fix GHSA-f83f-xpx7-ffpw

8d54be7
Select commit
Loading
Failed to load commit list.
StepSecurity Actions Security / StepSecurity Harden-Runner succeeded Dec 8, 2025 in 2m 38s

No anomalous activity on CI/CD runners

No new Harden-Runner detections for this pull request.

Details

Harden-Runner monitors all outbound traffic from each job at the DNS and network layers to ensure that CI/CD runners do not communicate with unauthorized destinations.
This reduces the risk of CI/CD secrets and source code being exfiltrated.

📋 Monitored GitHub Actions workflow runs

The following GitHub Actions workflow runs were monitored as part of this pull request.

Workflow Run ID Unique Destinations Actions Used Detailed Insights
lint.yaml 20041748518 10 5 View Insights
codeql 20041747538 - - Harden-Runner not enabled
approve-from-label.yaml 20041750973 - - Harden-Runner not enabled
approve-from-label.yaml 20041750878 - - Harden-Runner not enabled
approve-from-label.yaml 20041750771 - - Harden-Runner not enabled
wolfictl-lint.yaml 20041748507 1 3 View Insights
approve-from-label.yaml 20041964683 - - Harden-Runner not enabled
approve-from-label.yaml 20041750792 - - Harden-Runner not enabled
approve-from-label.yaml 20041750654 - - Harden-Runner not enabled

📚 Learn More

You can learn more about this GitHub check here