Re: [PR] Bump actions/dependency-review-action from 4 to 5 [camel-spring-boot]

2026-05-13 Thread via GitHub


Croway merged PR #1784:
URL: https://github.com/apache/camel-spring-boot/pull/1784


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]



[PR] Bump actions/dependency-review-action from 4 to 5 [camel-spring-boot]

2026-05-11 Thread via GitHub


dependabot[bot] opened a new pull request, #1784:
URL: https://github.com/apache/camel-spring-boot/pull/1784

   Bumps 
[actions/dependency-review-action](https://github.com/actions/dependency-review-action)
 from 4 to 5.
   
   Release notes
   Sourced from https://github.com/actions/dependency-review-action/releases";>actions/dependency-review-action's
 releases.
   
   5.0.0
   This is a new major version of the Dependency Review Action which updates 
the runtime to node24. This requires a minimum Actions Runner version https://github.com/actions/runner/releases/tag/v2.327.1";>v2.327.1 to 
run.
   What's Changed
   
   Add .github/copilot-instructions.md for Copilot coding agent by https://github.com/ahpook";>@​ahpook in https://redirect.github.com/actions/dependency-review-action/pull/1067";>actions/dependency-review-action#1067
   Update Node.js runtime from 20 to 24 by https://github.com/scottschreckengaust";>@​scottschreckengaust
 in https://redirect.github.com/actions/dependency-review-action/pull/1084";>actions/dependency-review-action#1084
   Bump spdx-license-ids from 3.0.20 to 3.0.23 by https://github.com/mongolyy";>@​mongolyy in https://redirect.github.com/actions/dependency-review-action/pull/1091";>actions/dependency-review-action#1091
   docs: bump actions/checkout from v4 to v6 in workflow examples by https://github.com/Marukome0743";>@​Marukome0743 in https://redirect.github.com/actions/dependency-review-action/pull/1077";>actions/dependency-review-action#1077
   fix: patched version display for advisories with non-strict semver 
ranges (e.g. Maven beta versions) by https://github.com/tspascoal";>@​tspascoal in https://redirect.github.com/actions/dependency-review-action/pull/1076";>actions/dependency-review-action#1076
   Resolve security findings by https://github.com/AshelyTC";>@​AshelyTC in https://redirect.github.com/actions/dependency-review-action/pull/1094";>actions/dependency-review-action#1094
   v5.0.0 release branch by https://github.com/ahpook";>@​ahpook in https://redirect.github.com/actions/dependency-review-action/pull/1098";>actions/dependency-review-action#1098
   
   New Contributors
   
   https://github.com/scottschreckengaust";>@​scottschreckengaust
 made their first contribution in https://redirect.github.com/actions/dependency-review-action/pull/1084";>actions/dependency-review-action#1084
   https://github.com/mongolyy";>@​mongolyy made 
their first contribution in https://redirect.github.com/actions/dependency-review-action/pull/1091";>actions/dependency-review-action#1091
   https://github.com/Marukome0743";>@​Marukome0743 made 
their first contribution in https://redirect.github.com/actions/dependency-review-action/pull/1077";>actions/dependency-review-action#1077
   
   Full Changelog: https://github.com/actions/dependency-review-action/compare/v4.9.0...v5.0.0";>https://github.com/actions/dependency-review-action/compare/v4.9.0...v5.0.0
   Dependency Review Action 4.9.0
   This feature release contains a couple of notable changes:
   
   There is a new configuration option show_patched_versions 
which will add a column to the output, showing the fix version of each 
vulnerable dependency. Thanks https://github.com/felickz";>@​felickz!
   Runs which do not display OpenSSF scorecards no longer fetch scorecard 
information; previously it was fetched regardless of whether or not it was 
displayed, causing unneccessary slowness. Great catch https://github.com/jantiebot";>@​jantiebot!
   There are a couple of fixes to purl parsing which should improve match 
accuracy for allow-package-dependency lists, including case 
(in)sensitivity and url-encoded namespaces Thanks https://github.com/juxtin";>@​juxtin!
   
   What's Changed
   
   Compare normalized purls to account for encoding quirks by https://github.com/juxtin";>@​juxtin in https://redirect.github.com/actions/dependency-review-action/pull/1056";>actions/dependency-review-action#1056
   Make purl comparisons case insensitive by https://github.com/juxtin";>@​juxtin in https://redirect.github.com/actions/dependency-review-action/pull/1057";>actions/dependency-review-action#1057
   Feat: Add Patched Version to Vulnerabilities 
summary by https://github.com/felickz";>@​felickz in 
https://redirect.github.com/actions/dependency-review-action/pull/1045";>actions/dependency-review-action#1045
   fix: only get scorecard levels if user wants to see the OpenSSF 
scorecard by https://github.com/jantiebot";>@​jantiebot in https://redirect.github.com/actions/dependency-review-action/pull/1060";>actions/dependency-review-action#1060
   Bump actions/stale from 10.1.0 to 10.2.0 by https://github.com/dependabot";>@​dependabot[bot] in https://redirect.github.com/actions/dependency-review-action/pull/1058";>actions/dependency-review-action#1058
   Bump actions/checkout from 4 to 6 by https://github.com/dependabot";>@​dependabot[bot] in https://redirect.github.com/actions/dependency-review-action/pull/1021";>actions/dependency-r