dependabot[bot] opened a new pull request, #1784:
URL: https://github.com/apache/camel-spring-boot/pull/1784
Bumps
[actions/dependency-review-action](https://github.com/actions/dependency-review-action)
from 4 to 5.
Release notes
Sourced from https://github.com/actions/dependency-review-action/releases";>actions/dependency-review-action's
releases.
5.0.0
This is a new major version of the Dependency Review Action which updates
the runtime to node24. This requires a minimum Actions Runner version https://github.com/actions/runner/releases/tag/v2.327.1";>v2.327.1 to
run.
What's Changed
Add .github/copilot-instructions.md for Copilot coding agent by https://github.com/ahpook";>@ahpook in https://redirect.github.com/actions/dependency-review-action/pull/1067";>actions/dependency-review-action#1067
Update Node.js runtime from 20 to 24 by https://github.com/scottschreckengaust";>@scottschreckengaust
in https://redirect.github.com/actions/dependency-review-action/pull/1084";>actions/dependency-review-action#1084
Bump spdx-license-ids from 3.0.20 to 3.0.23 by https://github.com/mongolyy";>@mongolyy in https://redirect.github.com/actions/dependency-review-action/pull/1091";>actions/dependency-review-action#1091
docs: bump actions/checkout from v4 to v6 in workflow examples by https://github.com/Marukome0743";>@Marukome0743 in https://redirect.github.com/actions/dependency-review-action/pull/1077";>actions/dependency-review-action#1077
fix: patched version display for advisories with non-strict semver
ranges (e.g. Maven beta versions) by https://github.com/tspascoal";>@tspascoal in https://redirect.github.com/actions/dependency-review-action/pull/1076";>actions/dependency-review-action#1076
Resolve security findings by https://github.com/AshelyTC";>@AshelyTC in https://redirect.github.com/actions/dependency-review-action/pull/1094";>actions/dependency-review-action#1094
v5.0.0 release branch by https://github.com/ahpook";>@ahpook in https://redirect.github.com/actions/dependency-review-action/pull/1098";>actions/dependency-review-action#1098
New Contributors
https://github.com/scottschreckengaust";>@scottschreckengaust
made their first contribution in https://redirect.github.com/actions/dependency-review-action/pull/1084";>actions/dependency-review-action#1084
https://github.com/mongolyy";>@mongolyy made
their first contribution in https://redirect.github.com/actions/dependency-review-action/pull/1091";>actions/dependency-review-action#1091
https://github.com/Marukome0743";>@Marukome0743 made
their first contribution in https://redirect.github.com/actions/dependency-review-action/pull/1077";>actions/dependency-review-action#1077
Full Changelog: https://github.com/actions/dependency-review-action/compare/v4.9.0...v5.0.0";>https://github.com/actions/dependency-review-action/compare/v4.9.0...v5.0.0
Dependency Review Action 4.9.0
This feature release contains a couple of notable changes:
There is a new configuration option show_patched_versions
which will add a column to the output, showing the fix version of each
vulnerable dependency. Thanks https://github.com/felickz";>@felickz!
Runs which do not display OpenSSF scorecards no longer fetch scorecard
information; previously it was fetched regardless of whether or not it was
displayed, causing unneccessary slowness. Great catch https://github.com/jantiebot";>@jantiebot!
There are a couple of fixes to purl parsing which should improve match
accuracy for allow-package-dependency lists, including case
(in)sensitivity and url-encoded namespaces Thanks https://github.com/juxtin";>@juxtin!
What's Changed
Compare normalized purls to account for encoding quirks by https://github.com/juxtin";>@juxtin in https://redirect.github.com/actions/dependency-review-action/pull/1056";>actions/dependency-review-action#1056
Make purl comparisons case insensitive by https://github.com/juxtin";>@juxtin in https://redirect.github.com/actions/dependency-review-action/pull/1057";>actions/dependency-review-action#1057
Feat: Add Patched Version to Vulnerabilities
summary by https://github.com/felickz";>@felickz in
https://redirect.github.com/actions/dependency-review-action/pull/1045";>actions/dependency-review-action#1045
fix: only get scorecard levels if user wants to see the OpenSSF
scorecard by https://github.com/jantiebot";>@jantiebot in https://redirect.github.com/actions/dependency-review-action/pull/1060";>actions/dependency-review-action#1060
Bump actions/stale from 10.1.0 to 10.2.0 by https://github.com/dependabot";>@dependabot[bot] in https://redirect.github.com/actions/dependency-review-action/pull/1058";>actions/dependency-review-action#1058
Bump actions/checkout from 4 to 6 by https://github.com/dependabot";>@dependabot[bot] in https://redirect.github.com/actions/dependency-review-action/pull/1021";>actions/dependency-r