-
Notifications
You must be signed in to change notification settings - Fork 675
Commit a36e128
authored
chore(deps): bump the github group with 2 updates (#4742)
Bumps the github group with 2 updates:
[actions/dependency-review-action](https://github.com/actions/dependency-review-action)
and
[actions/attest-build-provenance](https://github.com/actions/attest-build-provenance).
Updates `actions/dependency-review-action` from 4.7.2 to 4.7.3
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/dependency-review-action/releases">actions/dependency-review-action's
releases</a>.</em></p>
<blockquote>
<h2>4.7.3</h2>
<h2>What's Changed</h2>
<ul>
<li>Add explicit permissions to workflow files by <a
href="https://github.com/AshelyTC"><code>@AshelyTC</code></a> in <a
href="https://redirect.github.com/actions/dependency-review-action/pull/966">actions/dependency-review-action#966</a></li>
<li>Claire153/fix spamming mentioned issue by <a
href="https://github.com/claire153"><code>@claire153</code></a> in <a
href="https://redirect.github.com/actions/dependency-review-action/pull/974">actions/dependency-review-action#974</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/dependency-review-action/compare/v4...v4.7.3">https://github.com/actions/dependency-review-action/compare/v4...v4.7.3</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/dependency-review-action/commit/595b5aeba73380359d98a5e087f648dbb0edce1b"><code>595b5ae</code></a>
Update package version (<a
href="https://redirect.github.com/actions/dependency-review-action/issues/975">#975</a>)</li>
<li><a
href="https://github.com/actions/dependency-review-action/commit/fc5fd661aa443a25c657922b187812d85d3c6fa7"><code>fc5fd66</code></a>
Claire153/fix spamming mentioned issue (<a
href="https://redirect.github.com/actions/dependency-review-action/issues/974">#974</a>)</li>
<li><a
href="https://github.com/actions/dependency-review-action/commit/d38d1a4f40f1e9fd802865455d695d0ae924edee"><code>d38d1a4</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/dependency-review-action/issues/965">#965</a>
from actions/dependabot/npm_and_yarn/multi-c22e25d29b</li>
<li><a
href="https://github.com/actions/dependency-review-action/commit/8d420b827cac87791e1303cb1b01d3447e0bb8df"><code>8d420b8</code></a>
Merge branch 'main' into dependabot/npm_and_yarn/multi-c22e25d29b</li>
<li><a
href="https://github.com/actions/dependency-review-action/commit/bde01290d367cf6ae7232580700fcca870e35a80"><code>bde0129</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/dependency-review-action/issues/966">#966</a>
from actions/ashelytc/add-permissions</li>
<li><a
href="https://github.com/actions/dependency-review-action/commit/ab524903e88a228b6df0ab1dc878a34aebc28b70"><code>ab52490</code></a>
remove ruby</li>
<li><a
href="https://github.com/actions/dependency-review-action/commit/ef00a0afbb540db022eb79fc3aea57b5603d7a47"><code>ef00a0a</code></a>
add permissions to workflows</li>
<li><a
href="https://github.com/actions/dependency-review-action/commit/74c8179d39388ccd6863b1a230d2cd3e1d0de71d"><code>74c8179</code></a>
Bump brace-expansion</li>
<li>See full diff in <a
href="https://github.com/actions/dependency-review-action/compare/bc41886e18ea39df68b1b1245f4184881938e050...595b5aeba73380359d98a5e087f648dbb0edce1b">compare
view</a></li>
</ul>
</details>
<br />
Updates `actions/attest-build-provenance` from 2.4.0 to 3.0.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/attest-build-provenance/releases">actions/attest-build-provenance's
releases</a>.</em></p>
<blockquote>
<h2>v3.0.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Adjust node max-http-header-size setting by <a
href="https://github.com/bdehamer"><code>@bdehamer</code></a> in <a
href="https://redirect.github.com/actions/attest-build-provenance/pull/687">actions/attest-build-provenance#687</a></li>
<li>Bump actions/attest from v2.4.0 to <a
href="https://github.com/actions/attest/releases/tag/v3.0.0">v3.0.0</a>
by <a href="https://github.com/bdehamer"><code>@bdehamer</code></a> in
<a
href="https://redirect.github.com/actions/attest-build-provenance/pull/691">actions/attest-build-provenance#691</a>
<ul>
<li>Bump to node24 runtime</li>
<li>Improved checksum parsing</li>
</ul>
</li>
<li>Bump attest-build-provenance/predicate to v2.0.0 by <a
href="https://github.com/bdehamer"><code>@bdehamer</code></a> in <a
href="https://redirect.github.com/actions/attest-build-provenance/pull/693">actions/attest-build-provenance#693</a>
<ul>
<li>Bump to node24 runtime by <a
href="https://github.com/bdehamer"><code>@bdehamer</code></a> in <a
href="https://redirect.github.com/actions/attest-build-provenance/pull/692">actions/attest-build-provenance#692</a></li>
</ul>
</li>
</ul>
<h2>1 parent 6f2e4b1 commit a36e128Copy full SHA for a36e128
File tree
Expand file treeCollapse file tree
2 files changed
+2
-2
lines changedFilter options
- .github/workflows
Expand file treeCollapse file tree
2 files changed
+2
-2
lines changed.github/workflows/dependency-review.yml
Copy file name to clipboardExpand all lines: .github/workflows/dependency-review.yml+1-1Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
28 | 28 |
| |
29 | 29 |
| |
30 | 30 |
| |
31 |
| - | |
| 31 | + | |
32 | 32 |
| |
33 | 33 |
|
.github/workflows/release.yml
Copy file name to clipboardExpand all lines: .github/workflows/release.yml+1-1Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
53 | 53 |
| |
54 | 54 |
| |
55 | 55 |
| |
56 |
| - | |
| 56 | + | |
57 | 57 |
| |
58 | 58 |
| |
59 | 59 |
| |
|
0 commit comments