Created by: dependabot[bot]
Bumps actions/dependency-review-action from 2.0.4 to 2.1.0.
Release notes
Sourced from actions/dependency-review-action's releases.
2.1.0
This release includes a couple of new features (thanks
@WillDaSilva
and@tspascoal
):
- The Action now includes a summary of the vulnerabilities and licenses detected:
You can see a live example by visiting: https://github.com/future-funk/redesigned-custom-spood/actions/runs/2883016064
- You can now use the Action in events different to
pull_request
. You just need to provide ahead-sha
andbase-sha
in your config file:name: Dependency Review uses: actions/dependency-review-action@v2 with: # You can pass any git refs here # base-ref: ${{ your_base_ref }} # head-ref: ${{ your_head_ref }}
Commits
-
23d1fff
Bumping to 2.1.0. -
d792f3e
Add a reminder to update the version number in package.json -
5da7945
Fixing lint/dist. -
a8e7c37
Merge pull request #181 from tspascoal/add-summary -
0e0d6ec
Merge branch 'main' into add-summary -
9f2f2d8
Merge pull request #200 from actions/willdasilva-fork -
d201842
Clean up mock data setup. -
54af7c7
Merge branch 'main' into WillDaSilva-main. -
f2e57a1
Merge pull request #196 from actions/dependabot/npm_and_yarn/typescript-eslin... -
fb59017
Bump@typescript-eslint/eslint-plugin
from 5.33.0 to 5.33.1 - Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)