Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
chore(deps): update actions/dependency-review-action action to v4 (#2318
) [![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | action | major | `v2.5.1` -> `v4.1.3` | --- > [!WARNING] > Some dependencies could not be looked up. Check the Dependency Dashboard for more information. --- ### Release Notes <details> <summary>actions/dependency-review-action (actions/dependency-review-action)</summary> ### [`v4.1.3`](https://github.com/actions/dependency-review-action/releases/tag/v4.1.3): 4.1.3 [Compare Source](https://github.com/actions/dependency-review-action/compare/v4.1.2...v4.1.3) Fixes a bug in 4.1.2 that would introduce comments in every pull request, regardless of the user's configuration (see [actions/dependency-review-action#697). **Full Changelog**: actions/dependency-review-action@v4.1.2...v4.1.3 ### [`v4.1.2`](https://github.com/actions/dependency-review-action/releases/tag/v4.1.2): 4.1.2 [Compare Source](https://github.com/actions/dependency-review-action/compare/v4.1.1...v4.1.2) #### What's Changed - Expose dependency comment content by [@​jsoref](https://github.com/jsoref) in [actions/dependency-review-action#696 **Full Changelog**: actions/dependency-review-action@v4.1.1...v4.1.2 ### [`v4.1.1`](https://github.com/actions/dependency-review-action/releases/tag/v4.1.1): 4.1.1 [Compare Source](https://github.com/actions/dependency-review-action/compare/v4.1.0...v4.1.1) #### What's Changed - Bump `undici` to fix [GHSA-wqq4-5wpv-mx2g](https://github.com/nodejs/undici/security/advisories/GHSA-wqq4-5wpv-mx2g) - Bump [@​types/node](https://github.com/types/node) from 20.11.17 to 20.11.19 by [@​dependabot](https://github.com/dependabot) in [actions/dependency-review-action#693 **Full Changelog**: actions/dependency-review-action@v4.1.0...v4.1.1 ### [`v4.1.0`](https://github.com/actions/dependency-review-action/releases/tag/v4.1.0): 4.1.0 [Compare Source](https://github.com/actions/dependency-review-action/compare/v4.0.0...v4.1.0) #### What's Changed - Add `warn-only` by [@​tgrall](https://github.com/tgrall) in [actions/dependency-review-action#432 Added a new configuration option (`warn-only`, boolean) that makes the action always succeed while still displaying found vulnerabilities in the log. - Create stale.yaml by [@​jonjanego](https://github.com/jonjanego) in [actions/dependency-review-action#671 - Use manual codeql config by [@​juxtin](https://github.com/juxtin) in [actions/dependency-review-action#678 - Multiple dependency updates (see the changelog below for more information) #### New Contributors - [@​jonjanego](https://github.com/jonjanego) made their first contribution in [actions/dependency-review-action#671 - [@​tgrall](https://github.com/tgrall) made their first contribution in [actions/dependency-review-action#432 **Full Changelog**: actions/dependency-review-action@v4...v4.1.0 ### [`v4.0.0`](https://github.com/actions/dependency-review-action/releases/tag/v4.0.0) [Compare Source](https://github.com/actions/dependency-review-action/compare/v3.1.5...v4.0.0) - Update action to Node 20 by [@​takost](https://github.com/takost) in [actions/dependency-review-action#639 - Dependabot updates, see the full changelog for more details. #### New Contributors - [@​takost](https://github.com/takost) made their first contribution in [actions/dependency-review-action#639 **Full Changelog**: actions/dependency-review-action@v3.1.5...v4.0.0 ### [`v3.1.5`](https://github.com/actions/dependency-review-action/releases/tag/v3.1.5): 3.1.5 [Compare Source](https://github.com/actions/dependency-review-action/compare/v3.1.4...v3.1.5) #### What's Changed - Smaller `per_page` when requesting diff by [@​hmaurer](https://github.com/hmaurer) in [actions/dependency-review-action#649 - Update dependencies: - Bump [@​typescript-eslint/parser](https://github.com/typescript-eslint/parser) from 6.10.0 to 6.13.1 by [@​dependabot](https://github.com/dependabot) in [actions/dependency-review-action#630 - Bump prettier from 3.0.3 to 3.1.0 by [@​dependabot](https://github.com/dependabot) in [actions/dependency-review-action#629 - Bump [@​types/jest](https://github.com/types/jest) from 29.5.8 to 29.5.11 by [@​dependabot](https://github.com/dependabot) in [actions/dependency-review-action#637 - Bump nodemon from 3.0.1 to 3.0.2 by [@​dependabot](https://github.com/dependabot) in [actions/dependency-review-action#636 - Replace pip -> pypi in PURL examples by [@​febuiles](https://github.com/febuiles) in [actions/dependency-review-action#638 - Bump [@​typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/eslint-plugin) from 6.12.0 to 6.15.0 by [@​dependabot](https://github.com/dependabot) in [actions/dependency-review-action#644 - Bump eslint from 8.53.0 to 8.56.0 by [@​dependabot](https://github.com/dependabot) in [actions/dependency-review-action#640 - Bump [@​typescript-eslint/parser](https://github.com/typescript-eslint/parser) from 6.13.1 to 6.16.0 by [@​dependabot](https://github.com/dependabot) in [actions/dependency-review-action#645 - Bump prettier from 3.1.0 to 3.1.1 by [@​dependabot](https://github.com/dependabot) in [actions/dependency-review-action#646 **Full Changelog**: actions/dependency-review-action@v3.1.4...v3.1.5 ### [`v3.1.4`](https://github.com/actions/dependency-review-action/releases/tag/v3.1.4): 3.1.4 [Compare Source](https://github.com/actions/dependency-review-action/compare/v3.1.3...v3.1.4) #### What's Changed - Fixed a [bug](https://github.com/actions/dependency-review-action/issues/618) with severity filtering when using the `allow_ghsas` option: [actions/dependency-review-action#623. - Updates dependencies: - Bump [@​types/node](https://github.com/types/node) from 16.18.61 to 16.18.62 by [@​dependabot](https://github.com/dependabot) in [actions/dependency-review-action#619 action/pull/620 - Bump [@​typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/eslint-plugin) from 6.11.0 to 6.12.0 by [@​dependabot](https://github.com/dependabot) in [actions/dependency-review-action#625 - Bump typescript from 5.2.2 to 5.3.2 by [@​dependabot](https://github.com/dependabot) in [actions/dependency-review-action#624 **Full Changelog**: actions/dependency-review-action@v3...v3.1.4 ### [`v3.1.3`](https://github.com/actions/dependency-review-action/releases/tag/v3.1.3): 3.1.3 [Compare Source](https://github.com/actions/dependency-review-action/compare/v3.1.2...v3.1.3) #### What's Changed - Fixes purl "version must be percent-encoded" by [@​theztefan](https://github.com/theztefan) in [actions/dependency-review-action#617 **Full Changelog**: actions/dependency-review-action@v3...v3.1.3 ### [`v3.1.2`](https://github.com/actions/dependency-review-action/releases/tag/v3.1.2): 3.1.2 [Compare Source](https://github.com/actions/dependency-review-action/compare/v3.1.1...v3.1.2) #### What's Changed - Fix a regression for setups using self-hosted runners behind HTTP proxies:[@​febuiles](https://github.com/febuiles) in [actions/dependency-review-action#611 **Full Changelog**: actions/dependency-review-action@v3...v3.1.2 ### [`v3.1.1`](https://github.com/actions/dependency-review-action/releases/tag/v3.1.1): 3.1.1 [Compare Source](https://github.com/actions/dependency-review-action/compare/v3.1.0...v3.1.1) #### What's Changed - Update a bunch of dependencies, including major version upgrades for `octokit`, `@actions/github` and `typescript`. **Full Changelog**: actions/dependency-review-action@v3.1.0...v3.1.1 ### [`v3.1.0`](https://github.com/actions/dependency-review-action/releases/tag/v3.1.0): 3.1.0 [Compare Source](https://github.com/actions/dependency-review-action/compare/v3.0.8...v3.1.0) #### What's New Added support for dependencies submitted through the [dependency submission API](https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review#best-practices-for-using-the-dependency-review-api-and-the-dependency-submission-api-together). This includes two new configuration parameters: `retry-on-snapshot-warnings` and `retry-on-snapshot-warnings-timeout`. #### What's Changed - Fix(docs): Correct action input name by [@​oerd](https://github.com/oerd) in [actions/dependency-review-action#551 #### New Contributors - [@​oerd](https://github.com/oerd) made their first contribution in [actions/dependency-review-action#551 **Full Changelog**: actions/dependency-review-action@v3...v3.1.0 ### [`v3.0.8`](https://github.com/actions/dependency-review-action/releases/tag/v3.0.8): 3.0.8 [Compare Source](https://github.com/actions/dependency-review-action/compare/v3.0.7...v3.0.8) #### What's Changed Added `on-failure` option to `comment-summary-in-pr` setting by [@​sgmurphy](https://github.com/sgmurphy) in [actions/dependency-review-action#540 Previous configuration files using `true`/`false` for `comment-summary-in-pr` will be mapped automatically to the new values, but we encourage you to update to `always`/`on-failure`/`never`. #### New Contributors - [@​sgmurphy](https://github.com/sgmurphy) made their first contribution in [actions/dependency-review-action#540 **Full Changelog**: actions/dependency-review-action@v3...v3.0.8 ### [`v3.0.7`](https://github.com/actions/dependency-review-action/releases/tag/v3.0.7): 3.0.7 [Compare Source](https://github.com/actions/dependency-review-action/compare/v3.0.6...v3.0.7) #### What's Changed - Make GHES support / setup more clear by [@​rajbos](https://github.com/rajbos) in [actions/dependency-review-action#534 - Add an option to deny packages or groups of packages by [@​adrienpessu](https://github.com/adrienpessu) in [actions/dependency-review-action#544 #### New Contributors - [@​rajbos](https://github.com/rajbos) made their first contribution in [actions/dependency-review-action#534 - [@​adrienpessu](https://github.com/adrienpessu) made their first contribution in [actions/dependency-review-action#544 **Full Changelog**: actions/dependency-review-action@v3...v3.0.7 ### [`v3.0.6`](https://github.com/actions/dependency-review-action/releases/tag/v3.0.6): 3.0.6 [Compare Source](https://github.com/actions/dependency-review-action/compare/v3.0.5...v3.0.6) Fixes a bug introduced in 3.0.5 where we raised PURL errors when Dependency Graph returns an empty `package_url`. ### [`v3.0.5`](https://github.com/actions/dependency-review-action/releases/tag/v3.0.5): 3.0.5 [Compare Source](https://github.com/actions/dependency-review-action/compare/v3.0.4...v3.0.5) #### What's Changed Thanks to [@​theztefan](https://github.com/theztefan), we now have a new `allow-dependencies-licenses` option that takes a list of dependencies that will be excluded from license checks. See the [configuration options](https://github.com/actions/dependency-review-action#configuration-options) for more information on how to use it. - Exclude dependencies from license checks by [@​theztefan](https://github.com/theztefan) in [actions/dependency-review-action#423 - Documentation examples by [@​theztefan](https://github.com/theztefan) in [actions/dependency-review-action#423 - Show snapshot warnings in the summary by [@​juxtin](https://github.com/juxtin) in [actions/dependency-review-action#439 - Fix default values for fail-on-severity by [@​febuiles](https://github.com/febuiles) in [actions/dependency-review-action#451 - Updated dependencies. #### New Contributors - [@​juxtin](https://github.com/juxtin) made their first contribution in [actions/dependency-review-action#439 - [@​theztefan](https://github.com/theztefan) made their first contribution in [actions/dependency-review-action#423 **Full Changelog**: actions/dependency-review-action@v3...v3.0.5 ### [`v3.0.4`](https://github.com/actions/dependency-review-action/releases/tag/v3.0.4): 3.0.4 [Compare Source](https://github.com/actions/dependency-review-action/compare/v3.0.3...v3.0.4) #### What's New? The Action can now publish a comment in the pull request if the `comment-summary-in-pr` option is set. More information can be found in the [README](https://github.com/actions/dependency-review-action#configuration-options). #### New Contributors - [@​davelosert](https://github.com/davelosert) made their first contribution in [actions/dependency-review-action#393 #### Changelog - Write Summary as comment to the pull request by [@​davelosert](https://github.com/davelosert) in [actions/dependency-review-action#393 - Adjust summary format by [@​davelosert](https://github.com/davelosert) in [actions/dependency-review-action#416 - Security updates. **Full Changelog**: actions/dependency-review-action@v3...v3.0.4 ### [`v3.0.3`](https://github.com/actions/dependency-review-action/releases/tag/v3.0.3): 3.0.3 [Compare Source](https://github.com/actions/dependency-review-action/compare/v3.0.2...v3.0.3) #### What's Changed - Use cache in check-dist.yml by [@​jongwooo](https://github.com/jongwooo) in [actions/dependency-review-action#359 - Fix Dependency Review API response error handling by [@​felickz](https://github.com/felickz) in [actions/dependency-review-action#370 - Security updates #### New Contributors - [@​jongwooo](https://github.com/jongwooo) made their first contribution in [actions/dependency-review-action#359 - [@​felickz](https://github.com/felickz) made their first contribution in [actions/dependency-review-action#370 **Full Changelog**: actions/dependency-review-action@v3...v3.0.3 ### [`v3.0.2`](https://github.com/actions/dependency-review-action/releases/tag/v3.0.2): 3.0.2 [Compare Source](https://github.com/actions/dependency-review-action/compare/v3.0.1...v3.0.2) This release fixes spelling errors [actions/dependency-review-action#348 and upgrades dependencies to fix known vulnerabilities **Full Changelog**: actions/dependency-review-action@v3...v3.0.2 ### [`v3.0.1`](https://github.com/actions/dependency-review-action/releases/tag/v3.0.1): 3.0.1 [Compare Source](https://github.com/actions/dependency-review-action/compare/v3.0.0...v3.0.1) This release contains the following bugfixes: - Fixing API URL for GHES: [actions/dependency-review-action#331 - Improve list handling for external config files: [actions/dependency-review-action#330 **Full Changelog**: actions/dependency-review-action@v3...v3.0.1 ### [`v3.0.0`](https://github.com/actions/dependency-review-action/releases/tag/v3.0.0): 3.0.0 [Compare Source](https://github.com/actions/dependency-review-action/compare/v2.5.1...v3.0.0) #### Breaking Changes By default the action now expects [SPDX-compliant licenses](https://spdx.org/licenses/) everywhere. If you were previously using license names in the allow or deny lists make sure they're valid! #### What's Changed ##### Support for external configuration files You can now specify a [configuration file external to your repository](https://github.com/actions/dependency-review-action/#configuration-file). This allows organizations to have a single configuration file for all their repos. ##### Broader license support We've added support for a much broader set of project licenses by using GitHub's [Licenses API](https://docs.github.com/en/rest/licenses). ##### SPDX Compliance All of our license-related code now expects [SPDX-compliant licenses or expressions](https://spdx.org/licenses/). This allows us to standardize on a license naming scheme that already supports `OR`/`AND` expressions. ##### Disable individual checks You can now use the boolean options `license-check` and `vulnerability-check` to disable either one of the checks. More information in [our configuration options](https://github.com/actions/dependency-review-action/#configuration-options). #### Thanks Contributors for this release include: - [@​cnagadya](https://github.com/cnagadya) - [@​courtneycl](https://github.com/courtneycl) - [@​ericcornelissen](https://github.com/ericcornelissen) - [@​elireisman](https://github.com/elireisman) - [@​hmaurer](https://github.com/hmaurer) Thanks everyone! **Full Changelog**: actions/dependency-review-action@v2...v3.0.0 </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://developer.mend.io/github/defenseunicorns/zarf). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4yMDAuMCIsInVwZGF0ZWRJblZlciI6IjM3LjIwMC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiJ9--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
- Loading branch information