aRustyDev / aRustyDev/plan-mcp

deps: ci: bump actions/dependency-review-action from 4 to 5

Open
#12 0 comments 0 reactions 0 assignees View on GitHub
dependencies github-actions
Dominant language
No language data
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Description

## Dependabot Update

Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action) from 4 to 5.

Release notes

Sourced from actions/dependency-review-action's releases.



5.0.0


This is a new major version of the Dependency Review Action which updates the runtime to node24. This requires a minimum Actions Runner version v2.327.1 to run.


What's Changed



New Contributors



Full Changelog: https://github.com/actions/dependency-review-action/compare/v4.9.0...v5.0.0


Dependency Review Action 4.9.0


This feature release contains a couple of notable changes:



  • There is a new configuration option show_patched_versions which will add a column to the output, showing the fix version of each vulnerable dependency. Thanks @​felickz!

  • Runs which do not display OpenSSF scorecards no longer fetch scorecard information; previously it was fetched regardless of whether or not it was displayed, causing unneccessary slowness. Great catch @​jantiebot!

  • There are a couple of fixes to purl parsing which should improve match accuracy for allow-package-dependency lists, including case (in)sensitivity and url-encoded namespaces Thanks @​juxtin!


What's Changed



New Contributors



Full Changelog: https://github.com/actions/dependency-review-action/compare/v4.8.3...v4.9.0


4.8.3


Dependency Review Action v4.8.3


This is a bugfix release that updates a number of upstream dependencies and includes a fix for the earlier feature that detected oversized summaries and upload them as artifacts, which could occasionally crash the action.


We have also updated the release process to use a long-lived v4 branch for the action, instead of a force-pushed tag, which aligns better with git branching strategies; the change should be transparent to end users.


What's Changed



... (truncated)

Commits


  • a1d282b Merge pull request #1098 from actions/ahpook/v5-release

  • eb6c199 update examples to show @​v5

  • 3943c2c v5.0.0 release branch

  • 454943c Merge pull request #1094 from actions/ashelytc/security-findings

  • 6d92a12 revert @​typescript-eslint/parser update

  • a8e5a7e Merge pull request #1076 from tspascoal/fix-version-matching-for-non-string-s...

  • b6b7079 update @​typescript-eslint/parser to 8.40.0

  • 821a21d update more dependencies

  • 05aaaae run npm audit fix

  • 55d3e75 Merge pull request #1077 from Marukome0743/docs/checkout

  • Additional commits viewable in compare view


[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/dependency-review-action&package-manager=github_actions&previous-version=4&new-version=5)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

## Pull Request

- PR: #11
- Author: @dependabot[bot]
- URL: https://github.com/aRustyDev/plan-mcp/pull/11

---
This issue was automatically created to track the Dependabot update.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.