build(deps): bump actions/dependency-review-action from 3.0.6 to 4.2.4
Bumps actions/dependency-review-action from 3.0.6 to 4.2.4.
Release notes
Sourced from actions/dependency-review-action's releases.
v4.2.4
What's Changed
Fixed a bug in the output of OpenSSF cards for GitHub Actions.
New Contributors
@sporkmongermade their first contribution in actions/dependency-review-action#721Full Changelog: https://github.com/actions/dependency-review-action/compare/v4.2.3...v4.2.4
4.2.3
What's Changed
- Set comment as output by
@jsorefin actions/dependency-review-action#698- Add support for calculating OpenSSF Scorecards by
@jhutchings1in actions/dependency-review-action#709- Add outputs for the changes data by
@laughedelicin actions/dependency-review-action#707New Contributors
@jhutchings1made their first contribution in actions/dependency-review-action#709@laughedelicmade their first contribution in actions/dependency-review-action#707Full Changelog: https://github.com/actions/dependency-review-action/compare/v4.1.3...v4.2.3
4.1.3
Fixes a bug in 4.1.2 that would introduce comments in every pull request, regardless of the user's configuration (see actions/dependency-review-action#697).
Full Changelog: https://github.com/actions/dependency-review-action/compare/v4.1.2...v4.1.3
4.1.2
What's Changed
- Expose dependency comment content by
@jsorefin actions/dependency-review-action#696Full Changelog: https://github.com/actions/dependency-review-action/compare/v4.1.1...v4.1.2
4.1.1
What's Changed
- Bump
undicito fix GHSA-wqq4-5wpv-mx2g- Bump
@types/nodefrom 20.11.17 to 20.11.19 by@dependabotin actions/dependency-review-action#693Full Changelog: https://github.com/actions/dependency-review-action/compare/v4.1.0...v4.1.1
4.1.0
What's Changed
- Add
warn-onlyby@tgrallin actions/dependency-review-action#432Added a new configuration option (
warn-only, boolean) that makes the action always succeed while still displaying found vulnerabilities in the log.
- Create stale.yaml by
@jonjanegoin actions/dependency-review-action#671- Use manual codeql config by
@juxtinin actions/dependency-review-action#678- Multiple dependency updates (see the changelog below for more information)
... (truncated)
Commits
733dd5dbumping to 4.2.49093495Merge pull request #725 from actions/issue-71835b83b4Fix prettier issuese057056Add packaged code updated684d03Add trailing slash to tests2b0aaf1Fix extra slash issued920937Fix repositoryUrl issues around GitHub Actions02b13f6Merge pull request #721 from sporkmonger/patch-16e0fa26Typo fixes0fa40c3bumping to 4.2.3.- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)