Bump actions/dependency-review-action from 3.0.6 to 4.3.3
Bumps actions/dependency-review-action from 3.0.6 to 4.3.3.
Release notes
Sourced from actions/dependency-review-action's releases.
Notes for v4.3.3
What's Changed
- Allow slashes in purl package names by
@juxtinin actions/dependency-review-action#765- use the v3 version of the deps.dev API by
@josieangin actions/dependency-review-action#741- PR with suggestions - [Improvement]: Help streamline / simplify dependency review action README by
@am-steadin actions/dependency-review-action#773- fix show-openssf-scorecard-levels input by
@ramannin actions/dependency-review-action#776- Updates to the contribution guidelines by
@jonjanegoin actions/dependency-review-action#778- Create issue templates by
@jonjanegoin actions/dependency-review-action#777- Fix the max comment length issue by
@jhutchings1and@elireismanin actions/dependency-review-action#767- Bump project version to 4.3.3 in prep for a release by
@elireismanin actions/dependency-review-action#781New Contributors
@josieangmade their first contribution in actions/dependency-review-action#741@am-steadmade their first contribution in actions/dependency-review-action#773@ramannmade their first contribution in actions/dependency-review-action#776Full Changelog: https://github.com/actions/dependency-review-action/compare/v4.3.2...v4.3.3
v4.3.2
What's Changed
- Fix package-url parsing for allow-dependencies-licenses by
@juxtinin actions/dependency-review-action#761Full Changelog: https://github.com/actions/dependency-review-action/compare/v4.3.1...v4.3.2
v4.3.1
What's Changed
This release fixes some bugs related to package-url parsing that were introduced in 4.3.0. See actions/dependency-review-action#753.
Full Changelog: https://github.com/actions/dependency-review-action/compare/V4.3.0...v4.3.1
v4.3.0
New Features
- The
deny-packagesoption can now be used without a version number to exclude all versions of a package.What's Changed
- Fix action variable name for scorecard by
@lukehindsin actions/dependency-review-action#735- Fix extra https:// in summary by
@jhutchings1in actions/dependency-review-action#748- Bump typescript from 5.3.3 to 5.4.5 by
@dependabotin actions/dependency-review-action#744- Bump eslint-plugin-github from 4.10.1 to 4.10.2 by
@dependabotin actions/dependency-review-action#737- Show denied packages with red X by
@juxtinin actions/dependency-review-action#750- deny-packages configuration option can deny specified version or all packages by
@febuilesand@bteng22in actions/dependency-review-action#733New Contributors
@bteng22made their first contribution in actions/dependency-review-action#733@lukehindsmade their first contribution in actions/dependency-review-action#735Full Changelog: https://github.com/actions/dependency-review-action/compare/v4.2.5...V4.3.0
4.2.5
... (truncated)
Commits
72eb03dMerge pull request #781 from actions/release-v4.3.3137d8b4bump to version v4.3.3e6b618eMerge pull request #767 from actions/max-comment-length3c42649fix ws for linter8e6ea8dupdate packaging1b3d277post-review: add PR comment full summary test case220872cUpdate src/main.ts087d0f8repackage to update dist4531204whitespacedf1ca89appease linter- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)