Chore: Bump step-security/harden-runner from 2.14.1 to 2.14.2 83/15483/1
authordependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Mon, 9 Feb 2026 23:09:40 +0000 (23:09 +0000)
committeroran.gh2gerrit <releng+oran-gh2gerrit@linuxfoundation.org>
Mon, 9 Feb 2026 23:09:41 +0000 (23:09 +0000)
commit155314e1b9d5985ddb4b11d9c8eeb0ce4bff9edb
tree6e27b2b479b2a0ae7b9e4c85e532f361d123be5f
parent357fbb21d64991423f9ceb3336f5803b484a9f9d
Chore: Bump step-security/harden-runner from 2.14.1 to 2.14.2

Bumps step-security/harden-runner from 2.14.1 to 2.14.2.
## Release notes

Sourced from step-security/harden-runner's releases.

v2.14.2
What's Changed
Security fix: Fixed a medium severity vulnerability where outbound network connections using sendto, sendmsg, and sendmmsg socket system calls could bypass audit logging when using egress-policy: audit. This issue only affects the Community Tier in audit mode; block mode and Enterprise Tier were not affected. See GHSA-cpmj-h4f6-r6pq for details.
Full Changelog: https://github.com/step-security/harden-runner/compare/v2.14.1...v2.14.2

## Commits

5ef0c07 Merge pull request #635 from step-security/rc-34
eb43c7b update agent
See full diff in compare view

![Dependabot compatibility score](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Issue-ID: CIMAN-33
Signed-off-by: dependabot[bot] <support@github.com>
Change-Id: Ib565b2e6b40e5d95366215c6a97b5b4aae6fdabd
GitHub-PR: https://github.com/o-ran-sc/it-dep/pull/33
GitHub-Hash: e5c73ab07ee472a8
Signed-off-by: oran.gh2gerrit <releng+oran-gh2gerrit@linuxfoundation.org>
.github/workflows/gerrit-merge-itdep.yaml
.github/workflows/gerrit-merge-release-itdep.yaml
.github/workflows/gerrit-verify-itdep.yaml
.github/workflows/github2gerrit.yaml