Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 9, 2024

Bumps actions/dependency-review-action from 2.5.1 to 3.1.5.

Release notes

Sourced from actions/dependency-review-action's releases.

3.1.5

What's Changed

Full Changelog: actions/dependency-review-action@v3.1.4...v3.1.5

3.1.4

What's Changed

Full Changelog: actions/dependency-review-action@v3...v3.1.4

3.1.3

What's Changed

Full Changelog: actions/dependency-review-action@v3...v3.1.3

3.1.2

What's Changed

Full Changelog: actions/dependency-review-action@v3...v3.1.2

3.1.1

What's Changed

  • Update a bunch of dependencies, including major version upgrades for octokit, @actions/github and typescript.

... (truncated)

Commits
  • c74b580 Merge pull request #651 from actions/release-3.1.5
  • cc4f653 Release 3.1.5
  • d2ed7c0 Merge pull request #649 from actions/per-page
  • 9e77cc7 npm run package
  • b383a9a Smaller per_page when requesting diff
  • 8a49820 Merge pull request #646 from actions/dependabot/npm_and_yarn/prettier-3.1.1
  • a10a70d Merge pull request #645 from actions/dependabot/npm_and_yarn/typescript-eslin...
  • 0de1638 Bump prettier from 3.1.0 to 3.1.1
  • 522f021 Bump @​typescript-eslint/parser from 6.13.1 to 6.16.0
  • 2597ca4 Merge pull request #640 from actions/dependabot/npm_and_yarn/eslint-8.56.0
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot requested a review from a team January 9, 2024 15:51
@dependabot dependabot bot added dependencies github_actions Pull requests that update GitHub Actions code labels Jan 9, 2024
@boring-cyborg boring-cyborg bot added the automation This item relates to automation label Jan 9, 2024
@pull-request-size pull-request-size bot added the size/XS PR between 0-9 LOC label Jan 9, 2024
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action) from 2.5.1 to 3.1.5.
- [Release notes](https://github.com/actions/dependency-review-action/releases)
- [Commits](actions/dependency-review-action@0efb1d1...c74b580)

---
updated-dependencies:
- dependency-name: actions/dependency-review-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/github_actions/actions/dependency-review-action-3.1.5 branch from 2eb523b to b7b3c4c Compare January 9, 2024 15:55
@sonarqubecloud
Copy link

sonarqubecloud bot commented Jan 9, 2024

Quality Gate Passed Quality Gate passed

Kudos, no new issues were introduced!

0 New issues
0 Security Hotspots
No data about Coverage
No data about Duplication

See analysis details on SonarCloud

Copy link
Contributor

@am29d am29d left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dependabot merge

@dependabot dependabot bot merged commit f1c3c01 into main Jan 9, 2024
@dependabot dependabot bot deleted the dependabot/github_actions/actions/dependency-review-action-3.1.5 branch January 9, 2024 16:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automation This item relates to automation github_actions Pull requests that update GitHub Actions code size/XS PR between 0-9 LOC

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant