Closed dependabot[bot] closed 2 months ago
✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.
Package | Version | Score | Details | ||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
actions/github/codeql-action/upload-sarif | 2d790406f505036ef40ecba973cc774a50395aac | Unknown | Unknown | ||||||||||||||||||||||||||||||||||||||||||||||||
actions/actions/dependency-review-action | 5a2ce3f5b92ee19cbb1541a4984c76d921601d7c | :green_circle: 7.2 | Details
| ||||||||||||||||||||||||||||||||||||||||||||||||
actions/github/codeql-action/upload-sarif | 2d790406f505036ef40ecba973cc774a50395aac | Unknown | Unknown |
Bumps the github group with 2 updates in the / directory: github/codeql-action and actions/dependency-review-action.
Updates
github/codeql-action
from 3.25.11 to 3.25.13Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
2d79040
Merge pull request #2379 from github/update-v3.25.13-270a29d1c232a8bc
Update changelog for v3.25.13270a29d
Merge pull request #2375 from github/update-supported-enterprise-server-versions58f46da
Add changelog notef216681
Announce deprecation of CodeQL v2.13.4 and earlier8e14792
Merge pull request #2374 from github/aeisenberg/eslinte6663d9
Update supported GitHub Enterprise Server versions455bd98
Update checked-in dependencies778c2bc
Fix eslint configuration3cf7236
Migrate toeslint.config.mjs
Updates
actions/dependency-review-action
from 4.3.3 to 4.3.4Release notes
Sourced from actions/dependency-review-action's releases.
Commits
5a2ce3f
Merge pull request #791 from actions/juxtin/update-versionac6a6ad
Prepare even more for v4.3.43e2b917
Merge pull request #790 from actions/juxtin/update-versiond9ab9c8
Update version in package.json8c152c7
Merge pull request #769 from actions/dependabot/npm_and_yarn/zod-3.23.80085d30
Update dist08b5bf2
Bump zod from 3.22.4 to 3.23.8986fce9
Merge pull request #784 from actions/dependabot/npm_and_yarn/got-14.4.128743f8
Merge pull request #719 from actions/change-spdx-parserd6f34c3
Merge pull request #789 from actions/dependabot/npm_and_yarn/braces-3.0.3Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show