Chore: Bump step-security/harden-runner from 2.14.0 to 2.14.1 72/15472/1
authordependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Mon, 26 Jan 2026 21:41:24 +0000 (21:41 +0000)
committeroran.gh2gerrit <releng+oran-gh2gerrit@linuxfoundation.org>
Mon, 26 Jan 2026 21:41:25 +0000 (21:41 +0000)
commit846a525db85370d726db809d29f045848e141ad7
tree7a3d6e7c35a019305d48e55502158b7f5ba13739
parent0bb01bb77157b3626aa5a80791278f6c3b7a98a5
Chore: Bump step-security/harden-runner from 2.14.0 to 2.14.1

Bumps step-security/harden-runner from 2.14.0 to 2.14.1.
## Release notes

Sourced from step-security/harden-runner's releases.

v2.14.1
What's Changed

In some self-hosted environments, the agent could briefly fall back to public DNS resolvers during startup if the system DNS was not yet available. This behavior was unintended for GitHub-hosted runners and has now been fixed to prevent any use of public DNS resolvers.

Fixed npm audit vulnerabilities

Full Changelog: https://github.com/step-security/harden-runner/compare/v2.14.0...v2.14.1

## Commits

e3f713f Merge pull request #631 from step-security/rc-31
423acdd chore: fix npm audit vulnerabilities
0ddb86c update agent
See full diff in compare view

![Dependabot compatibility score](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Issue-ID: CIMAN-33
Signed-off-by: dependabot[bot] <support@github.com>
Change-Id: I5809958ff96c48d3e912528033307cb6fe231c57
GitHub-PR: https://github.com/o-ran-sc/it-dep/pull/30
GitHub-Hash: 83393f7afeb5a61f
Signed-off-by: oran.gh2gerrit <releng+oran-gh2gerrit@linuxfoundation.org>
.github/workflows/gerrit-merge-itdep.yaml
.github/workflows/gerrit-merge-release-itdep.yaml
.github/workflows/gerrit-verify-itdep.yaml
.github/workflows/github2gerrit.yaml