Skip to content

deps(ci)(deps): bump actions/dependency-review-action from 4 to 5 in the actions-core group across 1 directory#7

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-core-89cfe148ea
Open

deps(ci)(deps): bump actions/dependency-review-action from 4 to 5 in the actions-core group across 1 directory#7
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-core-89cfe148ea

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 11, 2026

Copy link
Copy Markdown

Bumps the actions-core group with 1 update in the / directory: actions/dependency-review-action.

Updates actions/dependency-review-action from 4 to 5

Release notes

Sourced from actions/dependency-review-action's releases.

5.0.0

This is a new major version of the Dependency Review Action which updates the runtime to node24. This requires a minimum Actions Runner version v2.327.1 to run.

What's Changed

New Contributors

Full Changelog: actions/dependency-review-action@v4.9.0...v5.0.0

Dependency Review Action 4.9.0

This feature release contains a couple of notable changes:

  • There is a new configuration option show_patched_versions which will add a column to the output, showing the fix version of each vulnerable dependency. Thanks @​felickz!
  • Runs which do not display OpenSSF scorecards no longer fetch scorecard information; previously it was fetched regardless of whether or not it was displayed, causing unneccessary slowness. Great catch @​jantiebot!
  • There are a couple of fixes to purl parsing which should improve match accuracy for allow-package-dependency lists, including case (in)sensitivity and url-encoded namespaces Thanks @​juxtin!

What's Changed

New Contributors

Full Changelog: actions/dependency-review-action@v4.8.3...v4.9.0

4.8.3

Dependency Review Action v4.8.3

This is a bugfix release that updates a number of upstream dependencies and includes a fix for the earlier feature that detected oversized summaries and upload them as artifacts, which could occasionally crash the action.

We have also updated the release process to use a long-lived v4 branch for the action, instead of a force-pushed tag, which aligns better with git branching strategies; the change should be transparent to end users.

What's Changed

... (truncated)

Commits
  • a1d282b Merge pull request #1098 from actions/ahpook/v5-release
  • eb6c199 update examples to show @​v5
  • 3943c2c v5.0.0 release branch
  • 454943c Merge pull request #1094 from actions/ashelytc/security-findings
  • 6d92a12 revert @​typescript-eslint/parser update
  • a8e5a7e Merge pull request #1076 from tspascoal/fix-version-matching-for-non-string-s...
  • b6b7079 update @​typescript-eslint/parser to 8.40.0
  • 821a21d update more dependencies
  • 05aaaae run npm audit fix
  • 55d3e75 Merge pull request #1077 from Marukome0743/docs/checkout
  • Additional commits viewable in compare view

@github-actions

github-actions Bot commented May 11, 2026

Copy link
Copy Markdown

📋 Unreleased Changelog Preview

This is what the next release notes will look like based on commits in this PR.

Changelog

All notable changes to this project will be documented in this file.

[Unreleased]

✨ Features

  • Added integrations tests — @nil-malh

  • Add integration test classes and configure JaCoCo for code coverage — @nil-malh

⬆️ Dependency Updates

🐛 Bug Fixes

  • Fixed integration-tests.yml that was failing trying to install ktestify-core from local — @nil-malh

🔧 Miscellaneous

  • Migrated workflows from GitHub PAT to GITHUB_TOKEN — @nil-malh

🎉 New Contributors


Generated by git-cliff


🔄 Run #24 · Mon, 18 May 2026 11:33:40 GMT

@github-actions

github-actions Bot commented May 11, 2026

Copy link
Copy Markdown

✅ Test Results

Metric Count
Passed 103
Failed 0
⏭️ Skipped 0
📊 Total 103

✅ Coverage

Type Coverage Covered / Total
📏 Lines 80.8% 286 / 354
🌿 Branches 64.8% 92 / 142
🔧 Methods 95.5% 64 / 67

🔄 CI run #43 · Mon, 15 Jun 2026 07:15:47 GMT

@dependabot dependabot Bot changed the title deps(ci)(deps): bump actions/dependency-review-action from 4 to 5 in the actions-core group deps(ci)(deps): bump actions/dependency-review-action from 4 to 5 in the actions-core group across 1 directory May 18, 2026
@dependabot dependabot Bot force-pushed the dependabot/github_actions/actions-core-89cfe148ea branch from 7c74016 to 18c0426 Compare May 18, 2026 11:33
Bumps the actions-core group with 1 update in the / directory: [actions/dependency-review-action](https://github.com/actions/dependency-review-action).


Updates `actions/dependency-review-action` from 4 to 5
- [Release notes](https://github.com/actions/dependency-review-action/releases)
- [Commits](actions/dependency-review-action@v4...v5)

---
updated-dependencies:
- dependency-name: actions/dependency-review-action
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions-core
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/github_actions/actions-core-89cfe148ea branch from 18c0426 to 7fc7bf1 Compare June 15, 2026 07:14
@dependabot dependabot Bot requested a review from nil-malh as a code owner June 15, 2026 07:14
@github-actions

Copy link
Copy Markdown

📋 Unreleased Changelog Preview

This is what the next release notes will look like based on commits in this PR.

Changelog

All notable changes to this project will be documented in this file.

[Unreleased]

Bug Fixes

  • Fixed integration-tests.yml that was failing trying to install ktestify-core from local — @nil-malh

Miscellaneous

  • Migrated workflows from GitHub PAT to GITHUB_TOKEN — @nil-malh

  • Removed codeql.yml to use GitHub's & fixed an issue with the release workflow. — @nil-malh

✨ Features

  • Added integrations tests — @nil-malh

  • Add integration test classes and configure JaCoCo for code coverage — @nil-malh

  • Add README.md and update changelog configuration — @nil-malh

⬆️ Dependency Updates

New Contributors


Generated by git-cliff


🔄 Run #38 · Mon, 15 Jun 2026 07:14:41 GMT

@github-actions

Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 1 package(s) with unknown licenses.
See the Details below.

License Issues

.github/workflows/dependency-review.yml

PackageVersionLicenseIssue Type
actions/dependency-review-action5.*.*NullUnknown License
Allowed Licenses: Apache-2.0, MIT, BSD-2-Clause, BSD-3-Clause, ISC, LGPL-2.0-only, LGPL-2.1-only, LGPL-2.1-or-later, EPL-1.0, EPL-2.0, CDDL-1.0, CC0-1.0

OpenSSF Scorecard

PackageVersionScoreDetails
actions/actions/dependency-review-action 5.*.* 🟢 7.7
Details
CheckScoreReason
Maintained🟢 1017 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Security-Policy🟢 9security policy file detected
Packaging⚠️ -1packaging workflow not detected
Code-Review🟢 10all changesets reviewed
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies⚠️ 1dependency not pinned by hash detected -- score normalized to 1
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection🟢 6branch protection is not maximal on development and all release branches
SAST🟢 9SAST tool detected but not run on all commits

Scanned Files

  • .github/workflows/dependency-review.yml

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants