chore(ci): bump actions/dependency-review-action from 4 to 5#112
chore(ci): bump actions/dependency-review-action from 4 to 5#112dependabot[bot] wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Greptile SummaryThis is a routine Dependabot bump of
Confidence Score: 5/5Safe to merge — single-line version bump with no logic changes. The change touches exactly one line in a CI workflow file, replacing the v4 tag with v5 on No files require special attention. Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[PR or Push to main] --> B{Event type?}
B -->|pull_request| C[dependency-review job]
B -->|push or schedule| D[codeql job]
C --> E[actions/checkout v6]
E --> F[dependency-review-action v5 - Node.js 24]
F --> G{High or critical\nvulnerabilities?}
G -->|Yes| H[Fail PR]
G -->|No| I[Pass]
D --> J[codeql-action init v4]
J --> K[Autobuild]
K --> L[CodeQL Analysis]
Reviews (1): Last reviewed commit: "chore(ci): bump actions/dependency-revie..." | Re-trigger Greptile |
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action) from 4 to 5. - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@v4...v5) --- updated-dependencies: - dependency-name: actions/dependency-review-action dependency-version: '5' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
5f17f38 to
9bc7cc5
Compare
Bumps actions/dependency-review-action from 4 to 5.
Release notes
Sourced from actions/dependency-review-action's releases.
... (truncated)
Commits
a1d282bMerge pull request #1098 from actions/ahpook/v5-releaseeb6c199update examples to show@v53943c2cv5.0.0 release branch454943cMerge pull request #1094 from actions/ashelytc/security-findings6d92a12revert@typescript-eslint/parserupdatea8e5a7eMerge pull request #1076 from tspascoal/fix-version-matching-for-non-string-s...b6b7079update@typescript-eslint/parserto 8.40.0821a21dupdate more dependencies05aaaaerun npm audit fix55d3e75Merge pull request #1077 from Marukome0743/docs/checkout