Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Update actions/dependency-review-action action to v4.3.2 (#2055)
[![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | action | minor | `v4.2.5` -> `v4.3.2` | --- ### Release Notes <details> <summary>actions/dependency-review-action (actions/dependency-review-action)</summary> ### [`v4.3.2`](https://github.com/actions/dependency-review-action/releases/tag/v4.3.2) [Compare Source](https://github.com/actions/dependency-review-action/compare/v4.3.1...v4.3.2) #### What's Changed - Fix package-url parsing for allow-dependencies-licenses by [@​juxtin](https://github.com/juxtin) in [https://github.com/actions/dependency-review-action/pull/761](https://github.com/actions/dependency-review-action/pull/761) **Full Changelog**: actions/dependency-review-action@v4.3.1...v4.3.2 ### [`v4.3.1`](https://github.com/actions/dependency-review-action/compare/v4.2.5...v4.3.1) [Compare Source](https://github.com/actions/dependency-review-action/compare/v4.3.0...v4.3.1) ### [`v4.3.0`](https://github.com/actions/dependency-review-action/releases/tag/v4.3.0) [Compare Source](https://github.com/actions/dependency-review-action/compare/v4.2.5...v4.3.0) #### New Features - The `deny-packages` option can now be used without a version number to exclude *all* versions of a package. #### What's Changed - Fix action variable name for scorecard by [@​lukehinds](https://github.com/lukehinds) in [https://github.com/actions/dependency-review-action/pull/735](https://github.com/actions/dependency-review-action/pull/735) - Fix extra https:// in summary by [@​jhutchings1](https://github.com/jhutchings1) in [https://github.com/actions/dependency-review-action/pull/748](https://github.com/actions/dependency-review-action/pull/748) - Bump typescript from 5.3.3 to 5.4.5 by [@​dependabot](https://github.com/dependabot) in [https://github.com/actions/dependency-review-action/pull/744](https://github.com/actions/dependency-review-action/pull/744) - Bump eslint-plugin-github from 4.10.1 to 4.10.2 by [@​dependabot](https://github.com/dependabot) in [https://github.com/actions/dependency-review-action/pull/737](https://github.com/actions/dependency-review-action/pull/737) - Show denied packages with red X by [@​juxtin](https://github.com/juxtin) in [https://github.com/actions/dependency-review-action/pull/750](https://github.com/actions/dependency-review-action/pull/750) - deny-packages configuration option can deny specified version or all packages by [@​febuiles](https://github.com/febuiles) and [@​bteng22](https://github.com/bteng22) in [https://github.com/actions/dependency-review-action/pull/733](https://github.com/actions/dependency-review-action/pull/733) #### New Contributors - [@​bteng22](https://github.com/bteng22) made their first contribution in [https://github.com/actions/dependency-review-action/pull/733](https://github.com/actions/dependency-review-action/pull/733) - [@​lukehinds](https://github.com/lukehinds) made their first contribution in [https://github.com/actions/dependency-review-action/pull/735](https://github.com/actions/dependency-review-action/pull/735) **Full Changelog**: actions/dependency-review-action@v4.2.5...V4.3.0 </details> --- ### Configuration 📅 **Schedule**: Branch creation - "monthly" (UTC), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://developer.mend.io/github/ni/nimble). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4zMjEuMiIsInVwZGF0ZWRJblZlciI6IjM3LjMyMS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> --------- Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: Milan Raj <rajsite@users.noreply.github.com>
- Loading branch information