Skip to content
This repository was archived by the owner on Apr 1, 2026. It is now read-only.

chore(deps): update actions/dependency-review-action action to v4.9.0#969

Merged
enechange-renovate[bot] merged 1 commit intomainfrom
renovate/github-actions
Mar 3, 2026
Merged

chore(deps): update actions/dependency-review-action action to v4.9.0#969
enechange-renovate[bot] merged 1 commit intomainfrom
renovate/github-actions

Conversation

@enechange-renovate
Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
actions/dependency-review-action action minor v4.8.3v4.9.0

Release Notes

actions/dependency-review-action (actions/dependency-review-action)

v4.9.0: Dependency Review Action 4.9.0

Compare Source

This feature release contains a couple of notable changes:

  • There is a new configuration option show_patched_versions which will add a column to the output, showing the fix version of each vulnerable dependency. Thanks @​felickz!
  • Runs which do not display OpenSSF scorecards no longer fetch scorecard information; previously it was fetched regardless of whether or not it was displayed, causing unneccessary slowness. Great catch @​jantiebot!
  • There are a couple of fixes to purl parsing which should improve match accuracy for allow-package-dependency lists, including case (in)sensitivity and url-encoded namespaces Thanks @​juxtin!

What's Changed

New Contributors

Full Changelog: actions/dependency-review-action@v4.8.3...v4.9.0


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@enechange-renovate enechange-renovate bot added the dependencies Pull requests that update a dependency file label Mar 3, 2026
@enechange-renovate enechange-renovate bot enabled auto-merge March 3, 2026 23:06
Copy link
Copy Markdown

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved automated PR

@github-actions
Copy link
Copy Markdown

github-actions bot commented Mar 3, 2026

Dependency Review

✅ No vulnerabilities found.

Scanned Files

  • .github/workflows/dependency-review.yml

@enechange-renovate enechange-renovate bot merged commit 0d40b74 into main Mar 3, 2026
7 checks passed
@enechange-renovate enechange-renovate bot deleted the renovate/github-actions branch March 3, 2026 23:07
@codecov
Copy link
Copy Markdown

codecov bot commented Mar 3, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 50.96%. Comparing base (d342c1d) to head (01a2174).
⚠️ Report is 4 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #969   +/-   ##
=======================================
  Coverage   50.96%   50.96%           
=======================================
  Files          26       26           
  Lines        1242     1242           
  Branches      178      178           
=======================================
  Hits          633      633           
  Misses        605      605           
  Partials        4        4           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants