Skip to content

Bump actions/dependency-review-action from 2.5.1 to 4.3.2#138

Merged
cameracker merged 1 commit into
masterfrom
dependabot/github_actions/actions/dependency-review-action-4.3.2
May 12, 2024
Merged

Bump actions/dependency-review-action from 2.5.1 to 4.3.2#138
cameracker merged 1 commit into
masterfrom
dependabot/github_actions/actions/dependency-review-action-4.3.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 12, 2024

Copy link
Copy Markdown
Contributor

Bumps actions/dependency-review-action from 2.5.1 to 4.3.2.

Release notes

Sourced from actions/dependency-review-action's releases.

v4.3.2

What's Changed

Full Changelog: actions/dependency-review-action@v4.3.1...v4.3.2

v4.3.1

What's Changed

This release fixes some bugs related to package-url parsing that were introduced in 4.3.0. See actions/dependency-review-action#753.

Full Changelog: actions/dependency-review-action@V4.3.0...v4.3.1

v4.3.0

New Features

  • The deny-packages option can now be used without a version number to exclude all versions of a package.

What's Changed

New Contributors

Full Changelog: actions/dependency-review-action@v4.2.5...V4.3.0

4.2.5

What's Changed

Full Changelog: actions/dependency-review-action@v4.2.4...v4.2.5

v4.2.4

What's Changed

Fixed a bug in the output of OpenSSF cards for GitHub Actions.

New Contributors

Full Changelog: actions/dependency-review-action@v4.2.3...v4.2.4

4.2.3

... (truncated)

Commits
  • 0c155c5 Merge pull request #762 from actions/juxtin/prepare-4.3.2
  • f3dac32 Merge pull request #761 from actions/juxtin/fix-allow-dependencies-licenses
  • d0d5cc3 Update version number to 4.3.2
  • 49fbbe0 Fix package-url parsing for allow-dependencies-licenses
  • e58c696 Merge pull request #758 from actions/juxtin/prepare-4.3.1
  • 9b7c72d Change version to 4.3.1
  • 7dcfabf Merge pull request #753 from actions/juxtin/debug-purl
  • 5f0808f Validate that deny-packages purls are complete
  • fcc66c2 Refine purl parsing and tests
  • 1dd418b Basic tests for PURL validation in config
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels May 12, 2024
@codecov

codecov Bot commented May 12, 2024

Copy link
Copy Markdown

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 100.00%. Comparing base (22c52c2) to head (2ce8dee).
Report is 6 commits behind head on master.

❗ Current head 2ce8dee differs from pull request most recent head cbc00f2. Consider uploading reports for the commit cbc00f2 to get more accurate results

Additional details and impacted files
@@            Coverage Diff            @@
##            master      #138   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files            4         4           
  Lines          513       531   +18     
=========================================
+ Hits           513       531   +18     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/dependency-review-action-4.3.2 branch from 2ce8dee to 3b1e917 Compare May 12, 2024 14:34
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action) from 2.5.1 to 4.3.2.
- [Release notes](https://github.com/actions/dependency-review-action/releases)
- [Commits](actions/dependency-review-action@0efb1d1...0c155c5)

---
updated-dependencies:
- dependency-name: actions/dependency-review-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/dependency-review-action-4.3.2 branch from 3b1e917 to cbc00f2 Compare May 12, 2024 14:35
@cameracker
cameracker merged commit 28d784d into master May 12, 2024
@dependabot
dependabot Bot deleted the dependabot/github_actions/actions/dependency-review-action-4.3.2 branch May 12, 2024 14:35
nono referenced this pull request in linagora/cozy-stack May 13, 2024
[![Mend
Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)

This PR contains the following updates:

| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [github.com/gofrs/uuid/v5](https://togithub.com/gofrs/uuid) | `v5.1.0`
-> `v5.2.0` |
[![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fgofrs%2fuuid%2fv5/v5.2.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![adoption](https://developer.mend.io/api/mc/badges/adoption/go/github.com%2fgofrs%2fuuid%2fv5/v5.2.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![passing](https://developer.mend.io/api/mc/badges/compatibility/go/github.com%2fgofrs%2fuuid%2fv5/v5.1.0/v5.2.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fgofrs%2fuuid%2fv5/v5.1.0/v5.2.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|

---

### Release Notes

<details>
<summary>gofrs/uuid (github.com/gofrs/uuid/v5)</summary>

### [`v5.2.0`](https://togithub.com/gofrs/uuid/releases/tag/v5.2.0)

[Compare
Source](https://togithub.com/gofrs/uuid/compare/v5.1.0...v5.2.0)

This minor release updates the UUID v6 and v7 features of package to be
complaint to draft RFC-9562, which replaces the previous family of uuid
drafts. Additionally, it adds more specific error types, and tunes up
Github Actions safety practices

#### What's Changed

- Update to RFC 9562 by
[@&#8203;kohenkatz](https://togithub.com/kohenkatz) in
[https://github.com/gofrs/uuid/pull/117](https://togithub.com/gofrs/uuid/pull/117)
- \[StepSecurity] Apply security best practices by
[@&#8203;step-security-bot](https://togithub.com/step-security-bot) in
[https://github.com/gofrs/uuid/pull/135](https://togithub.com/gofrs/uuid/pull/135)
- Bump actions/checkout from 2.7.0 to 4.1.5 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[https://github.com/gofrs/uuid/pull/137](https://togithub.com/gofrs/uuid/pull/137)
- Bump ossf/scorecard-action from 2.0.6 to 2.3.3 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[https://github.com/gofrs/uuid/pull/136](https://togithub.com/gofrs/uuid/pull/136)
- Bump actions/dependency-review-action from 2.5.1 to 4.3.2 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[https://github.com/gofrs/uuid/pull/138](https://togithub.com/gofrs/uuid/pull/138)
- Bump actions/upload-artifact from 3.1.3 to 4.3.3 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[https://github.com/gofrs/uuid/pull/140](https://togithub.com/gofrs/uuid/pull/140)
- Bump codecov/codecov-action from 2.1.0 to 4.3.1 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[https://github.com/gofrs/uuid/pull/139](https://togithub.com/gofrs/uuid/pull/139)
- Implemented support for checkable errors by
[@&#8203;PatrLind](https://togithub.com/PatrLind) in
[https://github.com/gofrs/uuid/pull/131](https://togithub.com/gofrs/uuid/pull/131)

#### New Contributors

- [@&#8203;kohenkatz](https://togithub.com/kohenkatz) made their first
contribution in
[https://github.com/gofrs/uuid/pull/117](https://togithub.com/gofrs/uuid/pull/117)
- [@&#8203;step-security-bot](https://togithub.com/step-security-bot)
made their first contribution in
[https://github.com/gofrs/uuid/pull/135](https://togithub.com/gofrs/uuid/pull/135)
- [@&#8203;dependabot](https://togithub.com/dependabot) made their first
contribution in
[https://github.com/gofrs/uuid/pull/137](https://togithub.com/gofrs/uuid/pull/137)
- [@&#8203;PatrLind](https://togithub.com/PatrLind) made their first
contribution in
[https://github.com/gofrs/uuid/pull/131](https://togithub.com/gofrs/uuid/pull/131)

**Full Changelog**:
gofrs/uuid@v5.1.0...v5.2.0

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "before 6am on Monday" in timezone
Europe/Paris, Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://www.mend.io/free-developer-tools/renovate/). View
repository job log
[here](https://developer.mend.io/github/cozy/cozy-stack).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4zNTEuMiIsInVwZGF0ZWRJblZlciI6IjM3LjM1MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=-->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant