Bump actions/dependency-review-action from 3.0.6 to 4.3.2
Bumps actions/dependency-review-action from 3.0.6 to 4.3.2.
Release notes
Sourced from actions/dependency-review-action's releases.
v4.3.2
What's Changed
- Fix package-url parsing for allow-dependencies-licenses by
@juxtinin actions/dependency-review-action#761Full Changelog: https://github.com/actions/dependency-review-action/compare/v4.3.1...v4.3.2
v4.3.1
What's Changed
This release fixes some bugs related to package-url parsing that were introduced in 4.3.0. See actions/dependency-review-action#753.
Full Changelog: https://github.com/actions/dependency-review-action/compare/V4.3.0...v4.3.1
v4.3.0
New Features
- The
deny-packagesoption can now be used without a version number to exclude all versions of a package.What's Changed
- Fix action variable name for scorecard by
@lukehindsin actions/dependency-review-action#735- Fix extra https:// in summary by
@jhutchings1in actions/dependency-review-action#748- Bump typescript from 5.3.3 to 5.4.5 by
@dependabotin actions/dependency-review-action#744- Bump eslint-plugin-github from 4.10.1 to 4.10.2 by
@dependabotin actions/dependency-review-action#737- Show denied packages with red X by
@juxtinin actions/dependency-review-action#750- deny-packages configuration option can deny specified version or all packages by
@febuilesand@bteng22in actions/dependency-review-action#733New Contributors
@bteng22made their first contribution in actions/dependency-review-action#733@lukehindsmade their first contribution in actions/dependency-review-action#735Full Changelog: https://github.com/actions/dependency-review-action/compare/v4.2.5...V4.3.0
4.2.5
What's Changed
- Fixed a bug where some configuration options in external files were not being properly picked up -- actions/dependency-review-action#722
- Bump eslint from 8.56.0 to 8.57.0
Full Changelog: https://github.com/actions/dependency-review-action/compare/v4.2.4...v4.2.5
v4.2.4
What's Changed
Fixed a bug in the output of OpenSSF cards for GitHub Actions.
New Contributors
@sporkmongermade their first contribution in actions/dependency-review-action#721Full Changelog: https://github.com/actions/dependency-review-action/compare/v4.2.3...v4.2.4
4.2.3
... (truncated)
Commits
0c155c5Merge pull request #762 from actions/juxtin/prepare-4.3.2f3dac32Merge pull request #761 from actions/juxtin/fix-allow-dependencies-licensesd0d5cc3Update version number to 4.3.249fbbe0Fix package-url parsing for allow-dependencies-licensese58c696Merge pull request #758 from actions/juxtin/prepare-4.3.19b7c72dChange version to 4.3.17dcfabfMerge pull request #753 from actions/juxtin/debug-purl5f0808fValidate that deny-packages purls are completefcc66c2Refine purl parsing and tests1dd418bBasic tests for PURL validation in config- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)