Created by: dependabot[bot]
Bumps actions/dependency-review-action from 2.1.0 to 2.4.0.
Release notes
Sourced from actions/dependency-review-action's releases.
2.4.0
We've added a new configuration option:
allow-ghsas
: Specify a list of various GitHub Advisory IDs you want the action to skip and not fail on.dependency-review: runs-on: ubuntu-latest steps: - name: 'Checkout Repository' uses: actions/checkout@v3 - name: 'Dependency Review' uses: actions/dependency-review-action@v2 with: allow-ghsas: 'GHSA-abcd-1234-5679, GHSA-efgh-1234-5679'
2.3.0
We're adding back support for an external configuration file. You can use the
config-file
configuration string to specify a path to a YAML configuration file where you can specify any options you want:dependency-review: runs-on: ubuntu-latest steps: - name: 'Checkout Repository' uses: actions/checkout@v3 - name: 'Dependency Review' uses: actions/dependency-review-action@v2 with: - config-file: ./.github/dependency-review-config.yml
2.2.0
We've added a new configuration option:
fail-on-scopes
: Specify whether you want the action to fail on vulnerabilities or license restrictions in dependencies that areruntime
,development
, or both. By default the action will only fail onruntime
dependencies.
Commits
-
375c537
Updating to 2.4.0 -
98f28eb
Merge pull request #251 from actions/sarahkemi/ghsa-allowlist -
716b322
add allow-ghsas input to action.yml -
12ae1bd
Update wording in README.md -
bcb5263
build and package allow-ghsas -
241ff73
add doc on allow-ghsas to readme -
062b749
revise ghsa filter -
4f00b72
filter allowed ghsas in action flow -
602f968
create a filter for vulns that are on the allowlist -
bd61ea0
create config option for ghsa allowlist - Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)