Skip to content

Release v2.21.0 - #684

Merged
varunsh-coder merged 12 commits into
mainfrom
rc-42
Aug 15, 2026
Merged

varunsh-coder merged 12 commits into
mainfrom
rc-42

Conversation

@varunsh-coder

Copy link
Copy Markdown
Member

Improvements to AWS CodeBuild Runner Support
Deny list feature for the enterprise tier
Minor bug fixes

rohan-stepsecurity and others added 8 commits August 12, 2026 10:58
bump linux tls-agent to v1.9.0 added denied endpoint changes
CodeBuild containers run as root without the `sudo` binary. Add a
`useDirectPrivileges` flag to bypass `sudo` for directory creation,
`chown`, and agent execution on CodeBuild. Also skip installation
when running inside a container without root privileges.
Regenerated dist bundles with ncc on Node 24 to resolve the
dist/pre/index.js.map conflict.
…f-v2

feat: avoid sudo when running as root
@github-actions

github-actions Bot commented Aug 14, 2026 •

Copy link
Copy Markdown

Test Results

78 tests  +5   78 ✅ +5   43s ⏱️ ±0s
 7 suites ±0    0 💤 ±0 
 1 files   ±0    0 ❌ ±0 

Results for commit 0f37afa. ± Comparison against base commit b09bb98.

♻️ This comment has been updated with latest results.

…oint inputs are set

The agent enforces the deny list only when allowed-endpoints is empty
(allowed endpoints always win). The action's cache-host discovery skip
now uses the same rule, so setting both inputs no longer skips the
discovery step while the agent enforces the allow list. Also log an
info message when both inputs are set to clarify that allowed-endpoints
is honored and denied-endpoints is ignored.
Look up the harden-runner cache entry before seeding it, so the
constant-key reservation no longer fails with a misleading log line on
every run after the first (#681). Guard the v2 lookup against the
cache-miss response ({ok: false, signedDownloadUrl: ""}) whose empty
URL previously threw, and seed the entry only on a miss, retrying the
lookup once afterward.

When the host still cannot be resolved, keep egress-policy set to
block instead of silently switching to audit (#675). The agents allow
the Actions cache endpoints implicitly, so this lookup is a
defense-in-depth addition and its failure is safe to ignore.

Fixes #675. Fixes #681.
The deny list is an enterprise (TLS) tier feature. The non-TLS agent
does not understand denied_endpoints, so a config with only
denied-endpoints set was treated as block with an empty allow list,
blocking all egress for the job. Gate deny-list mode on the TLS check
and ignore denied-endpoints with an info message when the org is not
on the enterprise tier.
@varunsh-coder
varunsh-coder merged commit 05e3151 into main Aug 15, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants