Bump actions/dependency-review-action from 3 to 4
Bumps actions/dependency-review-action from 3 to 4.
Release notes
Sourced from actions/dependency-review-action's releases.
v4.0.0
- Update action to Node 20 by
@takostin actions/dependency-review-action#639- Dependabot updates, see the full changelog for more details.
New Contributors
@takostmade their first contribution in actions/dependency-review-action#639Full Changelog: https://github.com/actions/dependency-review-action/compare/v3.1.5...v4.0.0
3.1.5
What's Changed
- Smaller
per_pagewhen requesting diff by@hmaurerin actions/dependency-review-action#649- Update dependencies:
- Bump
@typescript-eslint/parserfrom 6.10.0 to 6.13.1 by@dependabotin actions/dependency-review-action#630- Bump prettier from 3.0.3 to 3.1.0 by
@dependabotin actions/dependency-review-action#629- Bump
@types/jestfrom 29.5.8 to 29.5.11 by@dependabotin actions/dependency-review-action#637- Bump nodemon from 3.0.1 to 3.0.2 by
@dependabotin actions/dependency-review-action#636- Replace pip -> pypi in PURL examples by
@febuilesin actions/dependency-review-action#638- Bump
@typescript-eslint/eslint-pluginfrom 6.12.0 to 6.15.0 by@dependabotin actions/dependency-review-action#644- Bump eslint from 8.53.0 to 8.56.0 by
@dependabotin actions/dependency-review-action#640- Bump
@typescript-eslint/parserfrom 6.13.1 to 6.16.0 by@dependabotin actions/dependency-review-action#645- Bump prettier from 3.1.0 to 3.1.1 by
@dependabotin actions/dependency-review-action#646Full Changelog: https://github.com/actions/dependency-review-action/compare/v3.1.4...v3.1.5
3.1.4
What's Changed
Fixed a bug with severity filtering when using the
allow_ghsasoption: actions/dependency-review-action#623.Updates dependencies:
- Bump
@types/nodefrom 16.18.61 to 16.18.62 by@dependabotin actions/dependency-review-action#619 action/pull/620- Bump
@typescript-eslint/eslint-pluginfrom 6.11.0 to 6.12.0 by@dependabotin actions/dependency-review-action#625- Bump typescript from 5.2.2 to 5.3.2 by
@dependabotin actions/dependency-review-action#624Full Changelog: https://github.com/actions/dependency-review-action/compare/v3...v3.1.4
3.1.3
What's Changed
- Fixes purl "version must be percent-encoded" by
@theztefanin actions/dependency-review-action#617Full Changelog: https://github.com/actions/dependency-review-action/compare/v3...v3.1.3
3.1.2
What's Changed
- Fix a regression for setups using self-hosted runners behind HTTP proxies:
@febuilesin actions/dependency-review-action#611
... (truncated)
Commits
0c155c5Merge pull request #762 from actions/juxtin/prepare-4.3.2f3dac32Merge pull request #761 from actions/juxtin/fix-allow-dependencies-licensesd0d5cc3Update version number to 4.3.249fbbe0Fix package-url parsing for allow-dependencies-licensese58c696Merge pull request #758 from actions/juxtin/prepare-4.3.19b7c72dChange version to 4.3.17dcfabfMerge pull request #753 from actions/juxtin/debug-purl5f0808fValidate that deny-packages purls are completefcc66c2Refine purl parsing and tests1dd418bBasic tests for PURL validation in config- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)