Bump actions/dependency-review-action from 4.7.0 to 4.7.1
Merged
Number: #190
Type: Pull Request
State: Merged
Type: Pull Request
State: Merged
Author:
dependabot[bot]
Association: Contributor
Comments: 0
![dependabot[bot]](https://github.com/dependabot.png)
Association: Contributor
Comments: 0
Created:
May 14, 2025 at 03:35 AM UTC
(5 months ago)
(5 months ago)
Updated:
May 14, 2025 at 03:35 AM UTC
(5 months ago)
(5 months ago)
Merged:
May 14, 2025 at 03:35 AM UTC
(5 months ago)
by github-actions[bot]
(5 months ago)
by github-actions[bot]
Time to Close:
less than a minute
Labels:
dependencies github_actions
dependencies github_actions
Description:
Bumps actions/dependency-review-action from 4.7.0 to 4.7.1.
Release notes
Sourced from actions/dependency-review-action's releases.
v4.7.1
- Packages added to
allow-dependencies-licenses
will be allowed even if the package in question has no license information #889- License expressions (e.g.
Ruby OR GPL-2.0
) in the allow list are automatically discarded so that they don't invalidate the whole allow list, which should just be license identifier (e.g.Ruby
)
Commits
da24556
Merge pull request #933 from actions/dangoor/471-release9af0caf
Bump version number for 4.7.1d8f2df2
Merge pull request #932 from actions/907-disallow-expression6e9307a
Discard allow list entries that are not SPDX IDs8805179
Merge pull request #930 from actions/889-allow-no-license014300b
Update build34486f3
Check namespaces when excluding license checks9b155d6
Update buildf199659
Allowing dependencies works with no licenses- See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Pull Request Statistics
Commits:
1
1
Files Changed:
1
1
Additions:
+1
+1
Deletions:
-1
-1
Package Dependencies
Package:
actions/dependency-review-action
Ecosystem:
actions
actions
Version Change:
4.7.0 → 4.7.1
Update Type:
Patch
Patch
Technical Details
ID: | 1031392 |
UUID: | 2518072009 |
Node ID: | PR_kwDOIa0mA86WFrrJ |
Host: | GitHub |
Repository: | thomasleplus/spring-security-relative-host-header-redirection |
Merge State: | Unknown |