{"id":5806609,"name":"step-security/harden-runner","ecosystem":"actions","description":"Harden-Runner provides runtime security for GitHub-hosted and self-hosted runners","homepage":"https://www.stepsecurity.io","licenses":"apache-2.0","normalized_licenses":["Apache-2.0"],"repository_url":"https://github.com/step-security/harden-runner","keywords_array":["actions","egress-filtering","github-actions","hardening","network-security","runners","runtime-security","security-hardening","supply-chain-security"],"namespace":"step-security","versions_count":67,"first_release_published_at":"2021-11-19T15:21:41.000Z","latest_release_published_at":"2026-05-13T20:25:36.000Z","latest_release_number":"v2.19.2","last_synced_at":"2026-09-23T19:41:08.604Z","created_at":"2023-01-04T16:20:44.106Z","updated_at":"2026-09-23T19:41:08.604Z","registry_url":"https://github.com/step-security/harden-runner","install_command":null,"documentation_url":null,"metadata":{"name":"Harden-Runner","description":"Harden-Runner provides runtime security for GitHub-hosted and self-hosted runners","inputs":{"allowed-endpoints":{"description":"Only these endpoints will be allowed if egress-policy is set to block","required":false,"default":""},"denied-endpoints":{"description":"These endpoints will be denied when endpoint blocking is enabled","required":false,"default":""},"egress-policy":{"description":"Policy for outbound traffic, can be either audit or block","required":false,"default":"block"},"token":{"description":"Used to avoid github rate limiting","default":"${{ github.token }}"},"disable-telemetry":{"description":"Disable sending telemetry to StepSecurity API, can be set to true or false. This can only be set to true when egress-policy is set to block","required":false,"default":"false"},"disable-sudo":{"description":"Disable sudo access for the runner account. Note: This parameter will be deprecated in the future. Please use disable-sudo-and-containers instead.","required":false,"default":"false"},"disable-sudo-and-containers":{"description":"Disable sudo and container access for the runner account","required":false,"default":"false"},"disable-file-monitoring":{"description":"Disable file monitoring","required":false,"default":"false"},"policy":{"description":"Policy name to be used from the policy store. Requires id-token: write permission.","required":false,"default":""},"api-key":{"description":"StepSecurity API key for authenticating with the policy store. Required when use-policy-store is set to true.","required":false,"default":""},"use-policy-store":{"description":"Set to true to fetch policy from the policy store using the API key. This is the preferred method over the policy input which requires id-token: write permission. Policies can be defined and attached at workflow, repo, org, or cluster (for ARC) level in the policy store. The most granular policy will apply.","required":false,"default":"false"},"deploy-on-self-hosted-vm":{"description":"Set to true to deploy the Harden Runner agent directly on a self-hosted runner VM (Linux only). The recommended approach for self-hosted VMs is to bake the agent into the VM image; see docs.stepsecurity.io. Use this option only if baking is not possible, and only for ephemeral runners.","required":false,"default":"false"}},"branding":{"icon":"check-square","color":"green"},"runs":{"using":"node24","pre":"dist/pre/index.js","main":"dist/index.js","post":"dist/post/index.js"},"default_branch":"main","path":null},"repo_metadata":{"id":38015748,"uuid":"422287306","full_name":"step-security/harden-runner","owner":"step-security","description":"Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.","archived":false,"fork":false,"pushed_at":"2026-08-31T05:03:59.000Z","size":60663,"stargazers_count":1273,"open_issues_count":56,"forks_count":116,"subscribers_count":13,"default_branch":"main","last_synced_at":"2026-09-21T14:36:27.007Z","etag":null,"topics":["actions","egress-filtering","github-actions","hardening","network-security","runners","runtime-security","security-hardening","supply-chain-security"],"latest_commit_sha":null,"homepage":"https://www.stepsecurity.io","language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/step-security.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2021-10-28T16:58:46.000Z","updated_at":"2026-09-21T04:23:54.000Z","dependencies_parsed_at":"2025-12-10T21:00:57.546Z","dependency_job_id":null,"html_url":"https://github.com/step-security/harden-runner","commit_stats":{"total_commits":339,"total_committers":10,"mean_commits":33.9,"dds":0.4336283185840708,"last_synced_commit":"91182cccc01eb5e619899d80e4e971d6181294a7"},"previous_names":[],"tags_count":67,"template":false,"template_full_name":null,"purl":"pkg:github/step-security/harden-runner","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/step-security","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/sbom","scorecard":{"id":851154,"data":{"date":"2025-08-23T02:08:41Z","repo":{"name":"github.com/step-security/harden-runner","commit":"ec9f2d5744a09debf3a187a3f4f675c53b671911"},"scorecard":{"version":"v5.0.0","commit":"ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4"},"score":8.5,"checks":[{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#binary-artifacts"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#branch-protection"}},{"name":"CI-Tests","score":10,"reason":"7 out of 7 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#ci-tests"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#cii-best-practices"}},{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#code-review"}},{"name":"Contributors","score":6,"reason":"project has 2 contributing companies or organizations -- score normalized to 6","details":["Info: stepsecurity contributor org/company found, step-security contributor org/company found, "],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#contributors"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#dangerous-workflow"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yml:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#dependency-update-tool"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#license"}},{"name":"Maintained","score":10,"reason":"22 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#maintained"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#packaging"}},{"name":"Pinned-Dependencies","score":6,"reason":"dependency not pinned by hash detected -- score normalized to 6","details":["Warn: third-party GitHubAction not pinned by hash: .github/workflows/canary.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/step-security/harden-runner/canary.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/canary.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/step-security/harden-runner/canary.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/code-review.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/step-security/harden-runner/code-review.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-immutable-actions.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/step-security/harden-runner/publish-immutable-actions.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-immutable-actions.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/step-security/harden-runner/publish-immutable-actions.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/recurring-int-tests.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/step-security/harden-runner/recurring-int-tests.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/recurring-int-tests.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/step-security/harden-runner/recurring-int-tests.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/step-security/harden-runner/release.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/runs-on.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/step-security/harden-runner/runs-on.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/runs-on.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/step-security/harden-runner/runs-on.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/runs-on.yml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/step-security/harden-runner/runs-on.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/runs-on.yml:106: update your workflow using https://app.stepsecurity.io/secureworkflow/step-security/harden-runner/runs-on.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/runs-on.yml:140: update your workflow using https://app.stepsecurity.io/secureworkflow/step-security/harden-runner/runs-on.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/runs-on.yml:155: update your workflow using https://app.stepsecurity.io/secureworkflow/step-security/harden-runner/runs-on.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/runs-on.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/step-security/harden-runner/runs-on.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/runs-on.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/step-security/harden-runner/runs-on.yml/main?enable=pin","Info:  12 out of  18 GitHub-owned GitHubAction dependencies pinned","Info:  16 out of  26 third-party GitHubAction dependencies pinned","Info:   1 out of   1 npmCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#pinned-dependencies"}},{"name":"SAST","score":9,"reason":"SAST tool detected but not run on all commits","details":["Info: SAST configuration detected: CodeQL","Warn: 25 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#sast"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#security-policy"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#signed-releases"}},{"name":"Token-Permissions","score":10,"reason":"GitHub workflow tokens follow principle of least privilege","details":["Warn: jobLevel 'contents' permission set to 'write': .github/workflows/canary.yml:23","Info: jobLevel 'contents' permission set to 'read': .github/workflows/code-review.yml:10","Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/code-review.yml:11","Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql-analysis.yml:32","Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql-analysis.yml:31","Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish-immutable-actions.yml:14","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/publish-immutable-actions.yml:16","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release.yml:26","Info: jobLevel 'actions' permission set to 'read': .github/workflows/scorecards.yml:23","Info: jobLevel 'contents' permission set to 'read': .github/workflows/scorecards.yml:24","Warn: jobLevel 'checks' permission set to 'write': .github/workflows/test.yml:17","Info: topLevel 'contents' permission set to 'read': .github/workflows/canary.yml:16","Info: topLevel 'contents' permission set to 'read': .github/workflows/code-review.yml:5","Info: topLevel 'contents' permission set to 'read': .github/workflows/codeql-analysis.yml:24","Info: topLevel 'contents' permission set to 'read': .github/workflows/dependency-review.yml:13","Info: topLevel 'contents' permission set to 'read': .github/workflows/publish-immutable-actions.yml:8","Info: topLevel 'contents' permission set to 'read': .github/workflows/recurring-int-tests.yml:8","Info: topLevel 'contents' permission set to 'read': .github/workflows/release.yml:16","Info: topLevel 'contents' permission set to 'read': .github/workflows/runs-on.yml:7","Info: topLevel permissions set to 'read-all': .github/workflows/scorecards.yml:12","Info: topLevel 'contents' permission set to 'read': .github/workflows/test.yml:11"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#token-permissions"}},{"name":"Vulnerabilities","score":8,"reason":"2 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-fjxv-7rqg-78g4"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-23T22:35:54.413Z","repository_id":38015748,"created_at":"2025-08-23T22:35:54.414Z","updated_at":"2025-08-23T22:35:54.414Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":341189360,"owners_count":37572911,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-22T15:14:58.755Z","status":"online","status_checked_at":"2026-09-21T02:00:06.232Z","response_time":53,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"step-security","name":"StepSecurity","uuid":"88700172","kind":"organization","description":"Secure your GitHub Actions with StepSecurity: Your Trusted CI/CD Security Partner","email":"interest@stepsecurity.io","website":"https://www.stepsecurity.io","location":"United States of America","twitter":"step_security","company":null,"icon_url":"https://avatars.githubusercontent.com/u/88700172?v=4","repositories_count":603,"last_synced_at":"2026-09-17T20:33:31.325Z","metadata":{"has_sponsors_listing":false,"funding":null},"html_url":"https://github.com/step-security","funding_links":[],"total_stars":2856,"followers":253,"following":0,"created_at":"2022-11-14T05:19:49.352Z","updated_at":"2026-09-17T20:33:31.379Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/step-security","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/step-security/repositories"},"tags":[{"name":"v2.19.2","sha":"9ca718d3bf646d6534007c269a635b3e54cadf99","kind":"commit","published_at":"2026-05-13T20:25:36.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.19.2","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.19.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.19.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.19.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.19.2/manifests"},{"name":"v2.19.1","sha":"a5ad31d6a139d249332a2605b85202e8c0b78450","kind":"commit","published_at":"2026-05-02T06:21:23.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.19.1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.19.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.19.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.19.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.19.1/manifests"},{"name":"v2.19.0","sha":"8d3c67de8e2fe68ef647c8db1e6a09f647780f40","kind":"commit","published_at":"2026-04-20T07:33:22.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.19.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.19.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.19.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.19.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.19.0/manifests"},{"name":"v2.18.0","sha":"6c3c2f2c1c457b00c10c4848d6f5491db3b629df","kind":"commit","published_at":"2026-04-15T07:42:20.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.18.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.18.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.18.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.18.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.18.0/manifests"},{"name":"v2.17.0","sha":"f808768d1510423e83855289c910610ca9b43176","kind":"commit","published_at":"2026-04-09T06:47:46.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.17.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.17.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.17.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.17.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.17.0/manifests"},{"name":"v2.16.1","sha":"fe104658747b27e96e4f7e80cd0a94068e53901d","kind":"commit","published_at":"2026-03-30T18:43:08.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.16.1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.16.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.16.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.16.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.16.1/manifests"},{"name":"v2.16.0","sha":"fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594","kind":"commit","published_at":"2026-03-16T07:18:40.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.16.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.16.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.16.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.16.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.16.0/manifests"},{"name":"v2.15.1","sha":"58077d3c7e43986b6b15fba718e8ea69e387dfcc","kind":"commit","published_at":"2026-03-05T21:02:45.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.15.1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.15.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.15.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.15.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.15.1/manifests"},{"name":"v2.15.0","sha":"a90bcbc6539c36a85cdfeb73f7e2f433735f215b","kind":"commit","published_at":"2026-02-24T23:17:32.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.15.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.15.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.15.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.15.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.15.0/manifests"},{"name":"v2.14.2","sha":"5ef0c079ce82195b2a36a210272d6b661572d83e","kind":"commit","published_at":"2026-02-07T01:26:07.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.14.2","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.14.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.14.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.14.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.14.2/manifests"},{"name":"v2.14.1","sha":"e3f713f2d8f53843e71c69a996d56f51aa9adfb9","kind":"commit","published_at":"2026-01-26T05:01:21.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.14.1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.14.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.14.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.14.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.14.1/manifests"},{"name":"v2.14.0","sha":"20cf305ff2072d973412fa9b1e3a4f227bda3c76","kind":"commit","published_at":"2025-12-09T19:28:11.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.14.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.14.0","dependencies_parsed_at":"2026-01-07T21:07:44.685Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.14.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.14.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.14.0/manifests"},{"name":"v2.13.3","sha":"df199fb7be9f65074067a9eb93f12bb4c5547cf2","kind":"commit","published_at":"2025-12-02T04:45:08.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.13.3","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.13.3","dependencies_parsed_at":"2026-01-07T21:07:44.684Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.13.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.13.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.13.3/manifests"},{"name":"v2.13.2","sha":"95d9a5deda9de15063e7595e9719c11c38c90ae2","kind":"commit","published_at":"2025-11-05T07:36:48.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.13.2","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.13.2","dependencies_parsed_at":"2026-01-07T21:07:44.676Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.13.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.13.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.13.2/manifests"},{"name":"v2.13.1","sha":"f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a","kind":"commit","published_at":"2025-09-09T17:51:44.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.13.1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.13.1","dependencies_parsed_at":"2025-09-13T04:38:25.369Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.13.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.13.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.13.1/manifests"},{"name":"v2.13.0","sha":"ec9f2d5744a09debf3a187a3f4f675c53b671911","kind":"commit","published_at":"2025-07-15T19:29:13.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.13.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.13.0","dependencies_parsed_at":"2025-07-18T04:49:35.838Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.13.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.13.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.13.0/manifests"},{"name":"v2.12.2","sha":"6c439dc8bdf85cadbbce9ed30d1c7b959517bc49","kind":"commit","published_at":"2025-06-30T06:07:55.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.12.2","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.12.2","dependencies_parsed_at":"2025-07-03T04:21:19.381Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.12.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.12.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.12.2/manifests"},{"name":"v2.12.1","sha":"002fdce3c6a235733a90a27c80493a3241e56863","kind":"commit","published_at":"2025-06-11T14:18:17.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.12.1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.12.1","dependencies_parsed_at":"2025-06-13T04:22:34.960Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.12.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.12.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.12.1/manifests"},{"name":"v2.12.0","sha":"0634a2670c59f64b4a01f0f96f84700a4088b9f0","kind":"commit","published_at":"2025-04-21T19:01:51.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.12.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.12.0","dependencies_parsed_at":"2025-04-23T04:09:42.042Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.12.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.12.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.12.0/manifests"},{"name":"v2.11.1","sha":"c6295a65d1254861815972266d5933fd6e532bdf","kind":"commit","published_at":"2025-04-01T19:08:07.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.11.1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.11.1","dependencies_parsed_at":"2025-04-15T04:13:47.419Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.11.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.11.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.11.1/manifests"},{"name":"v2.11.0","sha":"4d991eb9b905ef189e4c376166672c3f2f230481","kind":"commit","published_at":"2025-02-15T20:40:48.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.11.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.11.0","dependencies_parsed_at":"2025-04-15T04:13:49.047Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.11.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.11.0/manifests"},{"name":"v2.10.4","sha":"cb605e52c26070c328afc4562f0b4ada7618a84e","kind":"commit","published_at":"2025-01-20T00:28:44.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.10.4","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.10.4","dependencies_parsed_at":"2025-02-09T05:05:47.698Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.10.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.10.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.10.4/manifests"},{"name":"v2.10.3","sha":"c95a14d0e5bab51a9f56296a4eb0e416910cd350","kind":"commit","published_at":"2025-01-09T20:45:26.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.10.3","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.10.3","dependencies_parsed_at":"2025-01-10T04:52:24.169Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.10.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.10.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.10.3/manifests"},{"name":"v2.10.2","sha":"0080882f6c36860b6ba35c610c98ce87d4e2f26f","kind":"commit","published_at":"2024-11-18T20:58:05.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.10.2","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.10.2","dependencies_parsed_at":"2024-11-20T04:09:22.127Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.10.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.10.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.10.2/manifests"},{"name":"v2.10.1","sha":"91182cccc01eb5e619899d80e4e971d6181294a7","kind":"commit","published_at":"2024-09-11T05:42:27.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.10.1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.10.1","dependencies_parsed_at":"2024-09-13T04:11:08.940Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.10.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.10.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.10.1/manifests"},{"name":"v2.10.0","sha":"446798f8213ac2e75931c1b0769676d927801858","kind":"commit","published_at":"2024-09-10T17:49:49.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.10.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.10.0","dependencies_parsed_at":"2024-09-12T04:20:26.577Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.10.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.10.0/manifests"},{"name":"v2.9.1","sha":"5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde","kind":"commit","published_at":"2024-08-05T22:25:32.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.9.1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.9.1","dependencies_parsed_at":"2024-08-11T05:37:18.232Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.9.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.9.1/manifests"},{"name":"v2.9.0","sha":"0d381219ddf674d61a7572ddd19d7941e271515c","kind":"commit","published_at":"2024-07-18T17:09:31.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.9.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.9.0","dependencies_parsed_at":"2024-07-30T04:13:39.982Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.9.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.9.0/manifests"},{"name":"v2.8.1","sha":"17d0e2bd7d51742c71671bd19fa12bdc9d40a3d6","kind":"commit","published_at":"2024-06-07T13:11:14.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.8.1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.8.1","dependencies_parsed_at":"2024-06-09T04:20:40.185Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.8.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.8.1/manifests"},{"name":"v2.8.0","sha":"f086349bfa2bd1361f7909c78558e816508cdc10","kind":"commit","published_at":"2024-05-22T00:40:44.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.8.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.8.0","dependencies_parsed_at":null,"dependency_job_id":"f0396892-f0cf-4fe2-82be-f339c6df41f1","purl":"pkg:github/step-security/harden-runner@v2.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.8.0/manifests"},{"name":"v2.7.1","sha":"a4aa98b93cab29d9b1101a6143fb8bce00e2eac4","kind":"commit","published_at":"2024-04-29T20:53:33.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.7.1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.7.1","dependencies_parsed_at":"2024-05-01T04:16:02.245Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.7.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.7.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.7.1/manifests"},{"name":"v2.7.0","sha":"63c24ba6bd7ba022e95695ff85de572c04a18142","kind":"commit","published_at":"2024-01-30T20:51:16.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.7.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.7.0","dependencies_parsed_at":"2024-02-03T04:18:35.997Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.7.0/manifests"},{"name":"v2.6.1","sha":"eb238b55efaa70779f274895e782ed17c84f2895","kind":"commit","published_at":"2023-11-16T20:43:19.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.6.1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.6.1","dependencies_parsed_at":"2023-11-18T04:14:18.078Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.6.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.6.1/manifests"},{"name":"v2.6.0","sha":"1b05615854632b887b69ae1be8cbefe72d3ae423","kind":"commit","published_at":"2023-10-03T01:00:54.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.6.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.6.0","dependencies_parsed_at":"2023-10-04T04:37:29.684Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.6.0/manifests"},{"name":"v2.5.1","sha":"8ca2b8b2ece13480cda6dacd3511b49857a23c09","kind":"commit","published_at":"2023-08-09T16:09:14.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.5.1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.5.1","dependencies_parsed_at":"2023-08-11T05:41:24.827Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.5.1/manifests"},{"name":"v2.5.0","sha":"cba0d00b1fc9a034e1e642ea0f1103c282990604","kind":"commit","published_at":"2023-07-24T18:30:49.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.5.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.5.0","dependencies_parsed_at":"2023-07-26T04:18:41.996Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.5.0/manifests"},{"name":"v2.4.1","sha":"55d479fb1c5bcad5a4f9099a5d9f37c8857b2845","kind":"commit","published_at":"2023-06-20T00:30:27.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.4.1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.4.1","dependencies_parsed_at":"2023-07-20T14:16:50.780Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.4.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.4.1/manifests"},{"name":"v2.4.0","sha":"128a63446a954579617e875aaab7d2978154e969","kind":"commit","published_at":"2023-05-04T20:39:03.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.4.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.4.0","dependencies_parsed_at":"2023-07-20T14:16:52.869Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.4.0/manifests"},{"name":"v2.3.1","sha":"6b3083af2869dc3314a0257a42f4af696cc79ba3","kind":"commit","published_at":"2023-04-19T20:06:04.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.3.1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.3.1","dependencies_parsed_at":"2023-07-20T14:16:51.506Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.3.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.3.1/manifests"},{"name":"v2.3.0","sha":"03bee3930647ebbf994244c21ddbc0d4933aab4f","kind":"commit","published_at":"2023-04-04T19:21:18.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.3.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.3.0","dependencies_parsed_at":"2023-07-20T14:16:52.829Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.3.0/manifests"},{"name":"v2.2.1","sha":"1f99358870fe1c846a3ccba386cc2b2246836776","kind":"commit","published_at":"2023-03-10T23:57:07.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.2.1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.2.1","dependencies_parsed_at":"2023-07-20T14:16:54.062Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.2.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.2.1/manifests"},{"name":"v2.2.0","sha":"c8454efe5d0bdefd25384362fe217428ca277d57","kind":"commit","published_at":"2023-02-20T16:00:04.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.2.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.2.0","dependencies_parsed_at":"2023-07-20T14:16:54.055Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.2.0/manifests"},{"name":"v2.1.0","sha":"18bf8ad2ca49c14cbb28b91346d626ccfb00c518","kind":"commit","published_at":"2023-01-13T18:30:06.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.1.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.1.0","dependencies_parsed_at":"2023-07-20T14:16:52.919Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.1.0/manifests"},{"name":"v2","sha":"ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5","kind":"commit","published_at":"2022-11-08T23:19:16.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2","dependencies_parsed_at":"2023-07-20T14:16:51.010Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2/manifests"},{"name":"v2.0.0","sha":"ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5","kind":"commit","published_at":"2022-11-08T23:19:16.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v2.0.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v2.0.0","dependencies_parsed_at":"2023-07-20T14:16:51.526Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v2.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v2.0.0/manifests"},{"name":"v1.5.0","sha":"2e205a28d0e1da00c5f53b161f4067b052c61f34","kind":"commit","published_at":"2022-09-29T17:35:13.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v1.5.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v1.5.0","dependencies_parsed_at":"2023-07-20T14:16:52.883Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v1.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.5.0/manifests"},{"name":"v1.4.5","sha":"dd2c410b088af7c0dc8046f3ac9a8f4148492a95","kind":"commit","published_at":"2022-08-12T17:28:41.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v1.4.5","html_url":"https://github.com/step-security/harden-runner/releases/tag/v1.4.5","dependencies_parsed_at":"2023-07-20T14:16:54.057Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v1.4.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.4.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.4.5/manifests"},{"name":"rc","sha":"dd2c410b088af7c0dc8046f3ac9a8f4148492a95","kind":"commit","published_at":"2022-08-12T17:28:41.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/rc","html_url":"https://github.com/step-security/harden-runner/releases/tag/rc","dependencies_parsed_at":"2023-07-20T14:16:53.373Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@rc","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/rc","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/rc/manifests"},{"name":"v1","sha":"dd2c410b088af7c0dc8046f3ac9a8f4148492a95","kind":"commit","published_at":"2022-08-12T17:28:41.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v1","dependencies_parsed_at":"2023-07-20T14:16:52.832Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1/manifests"},{"name":"v1.4.4","sha":"74b568e8591fbb3115c70f3436a0c6b0909a8504","kind":"commit","published_at":"2022-07-01T22:46:22.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v1.4.4","html_url":"https://github.com/step-security/harden-runner/releases/tag/v1.4.4","dependencies_parsed_at":"2023-07-20T14:16:53.403Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v1.4.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.4.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.4.4/manifests"},{"name":"v1.4.3","sha":"248ae51c2e8cc9622ecf50685c8bf7150c6e8813","kind":"commit","published_at":"2022-05-02T01:10:56.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v1.4.3","html_url":"https://github.com/step-security/harden-runner/releases/tag/v1.4.3","dependencies_parsed_at":"2023-07-20T14:16:52.828Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v1.4.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.4.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.4.3/manifests"},{"name":"v1.4.2","sha":"34cbc43f0b10c9dda284e663cf43c2ebaf83e956","kind":"commit","published_at":"2022-04-22T16:13:39.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v1.4.2","html_url":"https://github.com/step-security/harden-runner/releases/tag/v1.4.2","dependencies_parsed_at":"2023-07-20T14:16:52.875Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v1.4.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.4.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.4.2/manifests"},{"name":"v1.4.1","sha":"9b0655f430fba8c7001d4e38f8d4306db5c6e0ab","kind":"commit","published_at":"2022-03-18T21:59:57.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v1.4.1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v1.4.1","dependencies_parsed_at":"2023-07-20T14:16:52.861Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v1.4.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.4.1/manifests"},{"name":"v1.4.0","sha":"bdb12b622a910dfdc99a31fdfe6f45a16bc287a4","kind":"commit","published_at":"2022-02-13T16:33:49.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v1.4.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v1.4.0","dependencies_parsed_at":"2023-07-20T14:16:52.844Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v1.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.4.0/manifests"},{"name":"v1.3.0","sha":"14dc64f30986eaa2ad2dddcec073f5aab18e5a24","kind":"commit","published_at":"2022-01-12T03:52:48.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v1.3.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v1.3.0","dependencies_parsed_at":"2023-07-20T14:16:54.135Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v1.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.3.0/manifests"},{"name":"v1.2.0","sha":"382b675393c2c83a457a44e9bf5b129ec6995f38","kind":"commit","published_at":"2021-12-27T16:44:39.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v1.2.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v1.2.0","dependencies_parsed_at":"2023-07-20T14:16:51.467Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v1.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.2.0/manifests"},{"name":"v1.1.0","sha":"bb7f4132a6683afe78368c1ce7ec4cd5c132c993","kind":"commit","published_at":"2021-12-22T15:41:58.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v1.1.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v1.1.0","dependencies_parsed_at":"2023-07-20T14:16:54.097Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v1.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.1.0/manifests"},{"name":"v1.0.4","sha":"5d41baafe75a618828923a25ddbe5a7201085cc9","kind":"commit","published_at":"2021-12-18T00:41:42.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v1.0.4","html_url":"https://github.com/step-security/harden-runner/releases/tag/v1.0.4","dependencies_parsed_at":"2023-07-20T14:16:53.931Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v1.0.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.0.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.0.4/manifests"},{"name":"v1.0.3","sha":"50fa64266ccad6d5d09e10fe7cffde7c11034ed8","kind":"commit","published_at":"2021-12-17T20:57:04.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v1.0.3","html_url":"https://github.com/step-security/harden-runner/releases/tag/v1.0.3","dependencies_parsed_at":"2023-07-20T14:16:53.780Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v1.0.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.0.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.0.3/manifests"},{"name":"v1.0.2","sha":"dc71e894269c9d7314e1a161687b25f2b63b08d2","kind":"commit","published_at":"2021-12-15T17:07:30.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v1.0.2","html_url":"https://github.com/step-security/harden-runner/releases/tag/v1.0.2","dependencies_parsed_at":"2023-07-20T14:16:54.157Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v1.0.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.0.2/manifests"},{"name":"v1.0.1","sha":"99f91e655487198f8fad1b1984db68df32c15aea","kind":"commit","published_at":"2021-12-14T19:19:20.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v1.0.1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v1.0.1","dependencies_parsed_at":"2023-07-20T14:16:53.481Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v1.0.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.0.1/manifests"},{"name":"v1.0.0","sha":"4f04fa9d0868ba0694e878f4e36cd7a158ec6c93","kind":"commit","published_at":"2021-12-06T20:38:45.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v1.0.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v1.0.0","dependencies_parsed_at":"2023-07-20T14:16:52.694Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v1.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v1.0.0/manifests"},{"name":"v0.4.0","sha":"dea7bd51ad9ea3da09c16c60ecd5b9de22cb8e92","kind":"commit","published_at":"2021-11-30T23:30:42.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v0.4.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v0.4.0","dependencies_parsed_at":"2023-07-20T14:16:52.737Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v0.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v0.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v0.4.0/manifests"},{"name":"v0.3.0","sha":"917f7d59f22e82a5ddcaef409923426fd7aa6327","kind":"commit","published_at":"2021-11-26T16:33:57.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v0.3.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v0.3.0","dependencies_parsed_at":"2023-07-20T14:16:52.336Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v0.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v0.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v0.3.0/manifests"},{"name":"v0.2.0","sha":"9bba600d5283565b3a64a4803023bb25fc309c6c","kind":"commit","published_at":"2021-11-26T00:32:25.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v0.2.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v0.2.0","dependencies_parsed_at":"2023-07-20T14:16:52.801Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v0.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v0.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v0.2.0/manifests"},{"name":"v0.1.1","sha":"7206db2ec98c5538323a6d70e51f965d55c11c87","kind":"commit","published_at":"2021-11-20T14:53:37.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v0.1.1","html_url":"https://github.com/step-security/harden-runner/releases/tag/v0.1.1","dependencies_parsed_at":"2023-07-20T14:16:52.780Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v0.1.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v0.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v0.1.1/manifests"},{"name":"v0.1.0","sha":"ac43fb3d7391d5fe5788f2170c6c2c255400f844","kind":"commit","published_at":"2021-11-19T15:21:41.000Z","download_url":"https://codeload.github.com/step-security/harden-runner/tar.gz/v0.1.0","html_url":"https://github.com/step-security/harden-runner/releases/tag/v0.1.0","dependencies_parsed_at":"2023-07-20T14:16:51.373Z","dependency_job_id":null,"purl":"pkg:github/step-security/harden-runner@v0.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v0.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/tags/v0.1.0/manifests"}]},"repo_metadata_updated_at":"2026-09-22T16:20:29.308Z","dependent_packages_count":0,"downloads":null,"downloads_period":null,"dependent_repos_count":497,"rankings":{"downloads":null,"dependent_repos_count":1.5560133100934874,"dependent_packages_count":0.0,"stargazers_count":0.7352242116938679,"forks_count":2.861670099825701,"docker_downloads_count":null,"average":1.2882269054032642},"purl":"pkg:githubactions/step-security/harden-runner","advisories":[{"uuid":"GSA_kwCzR0hTQS00NmczLTM3cmgtdjY5OM4ABTwq","url":"https://github.com/advisories/GHSA-46g3-37rh-v698","title":"Egress Policy Bypass via DNS over HTTPS (DoH) in Harden-Runner (Community Tier)","description":"## Summary\n\nA vulnerability exists in the Community Tier of Harden-Runner that allows bypassing the `egress-policy: block` network restriction using DNS over HTTPS (DoH).\n\nHarden-Runner secures GitHub Actions workflows on runners by applying network policies, including an `allowed-endpoints` configuration that limits outbound traffic to specified domains and ports (e.g., `github.com:443`). In `egress-policy: block` mode, non-compliant connections are intercepted and denied. \n\nThis vulnerability exploits DoH, a protocol that encapsulates DNS queries within HTTPS requests. By crafting a DNS query that embeds exfiltrated data as a subdomain (e.g., encoding the runner's hostname into a label), an attacker can route the request through a permitted HTTPS endpoint like `dns.google` (`8.8.8.8`'s DoH service). The resolver processes the query and forwards it to the attacker's controlled domain, achieving exfiltration without directly accessing the blocked destination. This evades Harden-Runner's domain-based filtering, as the initial HTTPS connection appears legitimate. \n\nThis vulnerability requires the attacker to already have code execution capabilities within the GitHub Actions workflow.\n\nThe Enterprise Tier of Harden-Runner is **not affected** by this vulnerability.\n\n## Impact\n\nWhen Harden-Runner is configured with `egress-policy: block` and a restrictive `allowed-endpoints` list, an attacker with existing code execution capabilities within a GitHub Actions workflow can bypass the allowed domains check via DNS over HTTPS by proxying DNS queries through a permitted resolver (e.g., Google's DoH service). This allows data exfiltration even when `allowed-endpoints` is set to only whitelisted domains.\n\nThis vulnerability affects only the Community Tier. It requires the attacker to already have code execution capabilities within the GitHub Actions workflow.\n\n## Remediation\n\n### For Community Tier Users\n\nUpgrade to Harden-Runner v2.16.0 or later. \n\n### For Enterprise Tier Users\n\nNo action required. Enterprise tier customers are not affected by this vulnerability.\n\n## Credit \n\nWe would like to thank [Devansh Batham](https://github.com/devanshbatham) for responsibly disclosing this vulnerability through our security reporting process.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-03-17T18:38:16.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.6,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N","references":["https://github.com/step-security/harden-runner/security/advisories/GHSA-46g3-37rh-v698","https://github.com/step-security/harden-runner/releases/tag/v2.16.0","https://nvd.nist.gov/vuln/detail/CVE-2026-32947","https://github.com/advisories/GHSA-46g3-37rh-v698"],"source_kind":"github","identifiers":["GHSA-46g3-37rh-v698","CVE-2026-32947"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-03-17T19:00:10.311Z","updated_at":"2026-03-21T01:00:16.784Z","epss_percentage":0.00076,"epss_percentile":0.22588,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00NmczLTM3cmgtdjY5OM4ABTwq","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00NmczLTM3cmgtdjY5OM4ABTwq","packages":[{"ecosystem":"actions","package_name":"step-security/harden-runner","versions":[{"first_patched_version":"2.16.0","vulnerable_version_range":"\u003c= 2.15.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00NmczLTM3cmgtdjY5OM4ABTwq/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1nNjk5LTN4Nmctd20zZ84ABTwp","url":"https://github.com/advisories/GHSA-g699-3x6g-wm3g","title":"Egress Policy Bypass via DNS over TCP in Harden-Runner (Community Tier)","description":"## Summary\n\nA vulnerability exists in the Community Tier of Harden-Runner that allows bypassing the `egress-policy: block` network restriction using DNS queries over TCP.\n\nHarden-Runner enforces egress policies on GitHub runners by filtering outbound connections at the network layer. When `egress-policy: block` is enabled with a restrictive allowed-endpoints list (e.g., only `github.com:443`), all non-compliant traffic should be denied. However, DNS queries over TCP, commonly used for large responses or fallback from UDP, are not adequately restricted. Tools like `dig` can explicitly initiate TCP-based DNS queries (`+tcp` flag) without being blocked. \n\nThis vulnerability requires the attacker to already have code execution capabilities within the GitHub Actions workflow.\n\nThe Enterprise Tier of Harden-Runner is **not affected** by this vulnerability.\n\n## Impact\n\nWhen Harden-Runner is configured with `egress-policy: block` and a restrictive `allowed-endpoints` list, an attacker with existing code execution capabilities within a GitHub Actions workflow can bypass the egress block policy by initiating DNS queries over TCP to external resolvers. This allows outbound network communication that evades the configured network restrictions.\n\nThis vulnerability affects only the Community Tier. It requires the attacker to already have code execution capabilities within the GitHub Actions workflow.\n\n## Remediation\n\n### For Community Tier Users\n\nUpgrade to Harden-Runner v2.16.0 or later. \n\n### For Enterprise Tier Users\n\nNo action required. Enterprise tier customers are not affected by this vulnerability.\n\n## Credit \n\nWe would like to thank [Devansh Batham](https://github.com/devanshbatham) for responsibly disclosing this vulnerability through our security reporting process.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-03-17T18:37:46.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.6,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N","references":["https://github.com/step-security/harden-runner/security/advisories/GHSA-g699-3x6g-wm3g","https://github.com/step-security/harden-runner/releases/tag/v2.16.0","https://nvd.nist.gov/vuln/detail/CVE-2026-32946","https://github.com/advisories/GHSA-g699-3x6g-wm3g"],"source_kind":"github","identifiers":["GHSA-g699-3x6g-wm3g","CVE-2026-32946"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-03-17T19:00:10.311Z","updated_at":"2026-03-21T01:00:16.784Z","epss_percentage":0.00076,"epss_percentile":0.22588,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nNjk5LTN4Nmctd20zZ84ABTwp","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1nNjk5LTN4Nmctd20zZ84ABTwp","packages":[{"ecosystem":"actions","package_name":"step-security/harden-runner","versions":[{"first_patched_version":"2.16.0","vulnerable_version_range":"\u003c= 2.15.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nNjk5LTN4Nmctd20zZ84ABTwp/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1jcG1qLWg0ZjYtcjZwcc4ABSHS","url":"https://github.com/advisories/GHSA-cpmj-h4f6-r6pq","title":"Harden-Runner: Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)","description":"## Summary \n\nA security vulnerability has been identified in the Harden-Runner GitHub Action (Community Tier) that allows outbound network connections to evade audit logging. Specifically, outbound traffic using the `sendto`, `sendmsg`, and `sendmmsg` socket system calls can bypass detection and logging when using `egress-policy: audit`. \n\n**Note:** This vulnerability only affects audit mode. When using `egress-policy: block`, these connections are properly blocked. It requires the attacker to already have code execution capabilities within the GitHub Actions workflow (e.g., through workflow injection or compromised dependencies)\n\n## Affected Versions \n\n- Harden-Runner Community Tier: All versions prior to v2.14.2 \n- Harden-Runner Enterprise Tier: **NOT AFFECTED** \n\n## Severity \n\n**Medium** - This vulnerability affects audit logging capabilities but requires the attacker to already have code execution within the workflow. \n\n## Impact \n\nWhen Harden-Runner is configured in audit mode (`egress-policy: audit`), attackers with the ability to execute arbitrary code in a workflow can: \n- Send outbound network traffic without generating audit logs \n- Bypass network monitoring for UDP-based communications \n\n**Important:** This vulnerability requires the attacker to already have code execution capabilities within the GitHub Actions workflow (e.g., through workflow injection or compromised dependencies). \n\n## Technical Details \n\nThe vulnerability stems from incomplete monitoring coverage of certain socket-related system calls. Specifically, the following system calls can be used to send UDP traffic without triggering audit events: \n\n- `sendto()` \n\n- `sendmsg()` \n\n- `sendmmsg()` \n\nAn attacker with code execution in a workflow can compile and execute native code that uses these system calls to establish covert communication channels. \n\n## Affected Users \n\n**This vulnerability ONLY affects users of the Harden-Runner Community Tier.** \n\nThe Harden-Runner Enterprise Tier is **NOT vulnerable** to this bypass technique. \n\n## Remediation \n\n### For Community Tier Users \n \n**Upgrade to Harden-Runner v2.14.2 or later.** This version includes fixes for the logging bypass vulnerability. \n\n### For Enterprise Tier Users \n\nNo action required. Enterprise tier customers are not affected by this vulnerability. \n\n## Credit \n\nWe would like to thank [Devansh Batham](https://github.com/devanshbatham) for responsibly disclosing this vulnerability through our security reporting process. Devansh was communicative throughout the process and verified the fix before the fix before it was made public.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-02-09T17:19:14.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.0,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N","references":["https://github.com/step-security/harden-runner/security/advisories/GHSA-cpmj-h4f6-r6pq","https://github.com/step-security/harden-runner/commit/5ef0c079ce82195b2a36a210272d6b661572d83e","https://github.com/step-security/harden-runner/releases/tag/v2.14.2","https://nvd.nist.gov/vuln/detail/CVE-2026-25598","https://github.com/advisories/GHSA-cpmj-h4f6-r6pq"],"source_kind":"github","identifiers":["GHSA-cpmj-h4f6-r6pq","CVE-2026-25598"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-02-09T18:00:11.533Z","updated_at":"2026-03-14T01:00:46.835Z","epss_percentage":0.00018,"epss_percentile":0.04393,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jcG1qLWg0ZjYtcjZwcc4ABSHS","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1jcG1qLWg0ZjYtcjZwcc4ABSHS","packages":[{"ecosystem":"actions","package_name":"step-security/harden-runner","versions":[{"first_patched_version":"2.14.2","vulnerable_version_range":"\u003c 2.14.2"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jcG1qLWg0ZjYtcjZwcc4ABSHS/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1teHIzLTh3aGotajc0cs4ABHEj","url":"https://github.com/advisories/GHSA-mxr3-8whj-j74r","title":"Harden-Runner allows evasion of 'disable-sudo' policy","description":"### Summary\nHarden-Runner includes a policy option `disable-sudo` to prevent the GitHub Actions runner user from using sudo. This is implemented by removing the runner user from the sudoers file. However, this control can be bypassed as the runner user, being part of the docker group, can interact with the Docker daemon to launch privileged containers or access the host filesystem. This allows the attacker to regain root access or restore the sudoers file, effectively bypassing the restriction. \n\nFor an attacker to bypass this control, they would first need the ability to run their malicious code (e.g., by a supply chain attack similar to tj-actions or exploiting a Pwn Request vulnerability)) on the runner. This vulnerability has been fixed in Harden-Runner version `v2.12.0`.\n\n### Impact\nAn attacker with the ability to run their malicious code on a runner configured with `disable-sudo: true` can escalate privileges to root using Docker, defeating the intended security control.\n\n### Affected Configuration\n•\tHarden-Runner configurations that use `disable-sudo: true` on GitHub-hosted runners or on ephemeral self-hosted VM-based runners.\n•\tThis issue does not apply to Kubernetes-based Actions Runner Controller (ARC) Harden-Runner.\n\n### Mitigation / Fix\nThis vulnerability has been fixed in Harden-Runner version `v2.12.0`. Users should migrate to the stronger `disable-sudo-and-containers` policy. This setting:\n•\tDisables sudo access,\n•\tRemoves access to dockerd and containerd sockets,\n•\tUninstalls Docker from the runner entirely, preventing container-based privilege escalation paths.\n\n\n### Additional Improvements\n•\tThe `disable-sudo` option will be deprecated in the future, as it does not sufficiently restrict privilege escalation on its own. \n•\tHarden-Runner now includes detections to alert on attempts to evade the `disable-sudo` policy.\n\n\n### Credits\nReported by @loresuso and @darryk10. We would like to thank them for collaborating with us to mitigate the vulnerability.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-04-22T01:07:03.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.0,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H","references":["https://github.com/step-security/harden-runner/security/advisories/GHSA-mxr3-8whj-j74r","https://nvd.nist.gov/vuln/detail/CVE-2025-32955","https://github.com/step-security/harden-runner/commit/0634a2670c59f64b4a01f0f96f84700a4088b9f0","https://github.com/step-security/harden-runner/releases/tag/v2.12.0","https://github.com/advisories/GHSA-mxr3-8whj-j74r"],"source_kind":"github","identifiers":["GHSA-mxr3-8whj-j74r","CVE-2025-32955"],"repository_url":"https://github.com/step-security/harden-runner","blast_radius":1.0,"created_at":"2025-04-22T02:07:53.578Z","updated_at":"2026-02-16T01:01:48.936Z","epss_percentage":0.00076,"epss_percentile":0.22698,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1teHIzLTh3aGotajc0cs4ABHEj","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1teHIzLTh3aGotajc0cs4ABHEj","packages":[{"ecosystem":"actions","package_name":"step-security/harden-runner","versions":[{"first_patched_version":"2.12.0","vulnerable_version_range":"\u003e= 0.12.0, \u003c 2.12.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1teHIzLTh3aGotajc0cs4ABHEj/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1nODV2LXdmMjctNjd4Y84ABBec","url":"https://github.com/advisories/GHSA-g85v-wf27-67xc","title":"Harden-Runner has a command injection weaknesses in `setup.ts` and `arc-runner.ts`","description":"### Summary\n\nVersions of step-security/harden-runner prior to v2.10.2 contain multiple command injection weaknesses via environment variables that could potentially be exploited under specific conditions. However, due to the current execution order of pre-steps in GitHub Actions and the placement of harden-runner as the first step in a job, the likelihood of exploitation is low as the Harden-Runner action reads the environment variable during the pre-step stage. There are no known exploits at this time. \n\n### Details\n\n1. setup.ts:169 [1]  performs `execSync` with a command that gets\ninvoked after interpretation by the shell. This command includes an\ninterpolated `process.env.USER` variable, which an attacker could\nmodify (without actually creating a new user) to inject arbitrary\nshell expressions into this `execSync`. This may or may not be likely\nin practice, but I believe the hygienic way to perform the underlying\noperation is to use `execFileSync` or similar and bypass the\nunderlying shell evaluation.\n\n2. setup.ts:229 [2] has a nearly identical `execSync` to (1) above,\nbut with `$USER` for shell-level interpolation rather than string\ninterpolation. However, this is still injectable and would be best\nreplaced by an `execFileSync`, per above.\n\n3. arc-runner:40-44 [3] has an `execSync` with multiple string\ninterpolations. Most of these do not appear immediately injectible\n(since they appear to come from presumed trusted API responses), but\nthe expansion of `getRunnerTempDir()` may be injectable due to its\ndependence on potentially attacker-controllable environment variables\n(e.g. `RUNNER_TEMP`). The underlying operation appears to be a trivial\nfile copy, so this entire subprocess should in theory be replaceable\nwith ordinary NodeJS `fs` API calls instead.\n\n4. arc-runner:53 [4] demonstrates the same weakness, and has the same\nresolution as (3).\n\n5. arc-runner:57 demonstrates the same weakness as (3) and (4), and\nhas the same resolution.\n\n6. arc-runner:61 demonstrates the same weakness as (3), (4), and (5),\nand has the same resolution.\n\n\n[1]: https://github.com/step-security/harden-runner/blob/951b48540b429070694bc8abd82fd6901eb123ca/src/setup.ts#L169\n\n[2]: https://github.com/step-security/harden-runner/blob/951b48540b429070694bc8abd82fd6901eb123ca/src/setup.ts#L229\n\n[3]: https://github.com/step-security/harden-runner/blob/951b48540b429070694bc8abd82fd6901eb123ca/src/arc-runner.ts#L40-L44\n\n[4]: https://github.com/step-security/harden-runner/blob/951b48540b429070694bc8abd82fd6901eb123ca/src/arc-runner.ts#L53\n\n[5]: https://github.com/step-security/harden-runner/blob/951b48540b429070694bc8abd82fd6901eb123ca/src/arc-runner.ts#L57\n\n[6]: https://github.com/step-security/harden-runner/blob/951b48540b429070694bc8abd82fd6901eb123ca/src/arc-runner.ts#L61","origin":"UNSPECIFIED","severity":"LOW","published_at":"2024-11-18T23:48:26.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":2.7,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","references":["https://github.com/step-security/harden-runner/security/advisories/GHSA-g85v-wf27-67xc","https://github.com/step-security/harden-runner/commit/0080882f6c36860b6ba35c610c98ce87d4e2f26f","https://nvd.nist.gov/vuln/detail/CVE-2024-52587","https://github.com/step-security/harden-runner/blob/951b48540b429070694bc8abd82fd6901eb123ca/src/arc-runner.ts#L40-L44","https://github.com/step-security/harden-runner/blob/951b48540b429070694bc8abd82fd6901eb123ca/src/arc-runner.ts#L53","https://github.com/step-security/harden-runner/blob/951b48540b429070694bc8abd82fd6901eb123ca/src/arc-runner.ts#L57","https://github.com/step-security/harden-runner/blob/951b48540b429070694bc8abd82fd6901eb123ca/src/arc-runner.ts#L61","https://github.com/step-security/harden-runner/blob/951b48540b429070694bc8abd82fd6901eb123ca/src/setup.ts#L169","https://github.com/step-security/harden-runner/blob/951b48540b429070694bc8abd82fd6901eb123ca/src/setup.ts#L229","https://github.com/advisories/GHSA-g85v-wf27-67xc"],"source_kind":"github","identifiers":["GHSA-g85v-wf27-67xc","CVE-2024-52587"],"repository_url":"https://github.com/step-security/harden-runner","blast_radius":1.0,"created_at":"2024-11-19T00:06:52.463Z","updated_at":"2026-02-22T01:02:34.323Z","epss_percentage":0.01485,"epss_percentile":0.80752,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nODV2LXdmMjctNjd4Y84ABBec","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1nODV2LXdmMjctNjd4Y84ABBec","packages":[{"ecosystem":"actions","package_name":"step-security/harden-runner","versions":[{"first_patched_version":"2.10.2","vulnerable_version_range":"\u003c 2.10.2"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nODV2LXdmMjctNjd4Y84ABBec/related_packages","related_advisories":[]}],"docker_usage_url":"https://docker.ecosyste.ms/usage/actions/step-security/harden-runner","docker_dependents_count":5,"docker_downloads_count":717541575,"usage_url":"https://repos.ecosyste.ms/usage/actions/step-security/harden-runner","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/actions/step-security/harden-runner/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":{"last_synced_at":"2026-09-21T10:03:07.808Z","issues_count":65,"pull_requests_count":517,"avg_time_to_close_issue":8620355.06521739,"avg_time_to_close_pull_request":1302342.1126436782,"issues_closed_count":46,"pull_requests_closed_count":435,"pull_request_authors_count":34,"issue_authors_count":32,"avg_comments_per_issue":2.2153846153846155,"avg_comments_per_pull_request":1.2030947775628626,"merged_pull_requests_count":208,"bot_issues_count":12,"bot_pull_requests_count":327,"past_year_issues_count":13,"past_year_pull_requests_count":51,"past_year_avg_time_to_close_issue":2145211.5714285714,"past_year_avg_time_to_close_pull_request":415254.14285714284,"past_year_issues_closed_count":7,"past_year_pull_requests_closed_count":28,"past_year_pull_request_authors_count":19,"past_year_issue_authors_count":10,"past_year_avg_comments_per_issue":2.076923076923077,"past_year_avg_comments_per_pull_request":0.6274509803921569,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":8,"past_year_merged_pull_requests_count":19,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fharden-runner/issues","maintainers":[{"login":"varunsh-coder","count":106,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/varunsh-coder"},{"login":"h0x0er","count":40,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/h0x0er"},{"login":"rohan-stepsecurity","count":8,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/rohan-stepsecurity"},{"login":"ashishkurmi","count":7,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ashishkurmi"},{"login":"Devils-Knight","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Devils-Knight"},{"login":"arjundashrath","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/arjundashrath"}],"active_maintainers":[{"login":"varunsh-coder","count":15,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/varunsh-coder"},{"login":"h0x0er","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/h0x0er"},{"login":"rohan-stepsecurity","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/rohan-stepsecurity"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/github%20actions/packages/step-security%2Fharden-runner/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/github%20actions/packages/step-security%2Fharden-runner/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/github%20actions/packages/step-security%2Fharden-runner/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/github%20actions/packages/step-security%2Fharden-runner/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/github%20actions/packages/step-security%2Fharden-runner/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/github%20actions/packages/step-security%2Fharden-runner/codemeta","maintainers":[]}