Build(deps): Bump actions/dependency-review-action from 4.7.1 to 4.7.3#1253
Build(deps): Bump actions/dependency-review-action from 4.7.1 to 4.7.3#1253dependabot[bot] wants to merge 3 commits intomainfrom
Conversation
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action) from 4.7.1 to 4.7.3. - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@da24556...595b5ae) --- updated-dependencies: - dependency-name: actions/dependency-review-action dependency-version: 4.7.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
…-review-action-4.7.3
…-review-action-4.7.3
|
@dependabot rebase. |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
|
A newer version of actions/dependency-review-action exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged. |
Consolidate open dependabot PRs into a single commit: Python (tests/validation/requirements.txt): - cryptography: 45.0.5 -> 46.0.6 (fixes CVE-2026-26007 HIGH, CVE-2026-34073) - Pygments: 2.19.2 -> 2.20.0 - requests: 2.32.4 -> 2.33.0 (fixes CVE-2026-25645) GitHub Actions (.github/workflows/*.yml): - step-security/harden-runner: 2.12.2 -> 2.13.0 (all workflows) - docker/setup-buildx-action: 3.4.0/3.10.0 -> 3.11.1 - docker/build-push-action: 6.16.0 -> 6.18.0 - docker/login-action: 3.4.0 -> 3.5.0 - actions/dependency-review-action: 4.7.1 -> 4.7.3 Skipped PRs: - pyasn1 0.4.8 -> 0.6.3: blocked by mfd-powermanagement==1.12.0 pinning pyasn1==0.4.8 (no security advisories for 0.4.8) - cryptography 45.0.5 -> 46.0.5: superseded by 46.0.6 bump Addresses: #1225, #1226, #1227, #1253, #1254, #1434, #1464, #1466, #1469, #1471 Signed-off-by: Kasiewicz, Marek <marek.kasiewicz@intel.com>
Consolidate open dependabot PRs into a single commit: Python (tests/validation/requirements.txt): - cryptography: 45.0.5 -> 46.0.6 (fixes CVE-2026-26007 HIGH, CVE-2026-34073) - Pygments: 2.19.2 -> 2.20.0 - requests: 2.32.4 -> 2.33.0 (fixes CVE-2026-25645) GitHub Actions (.github/workflows/*.yml): - step-security/harden-runner: 2.12.2 -> 2.13.0 (all workflows) - docker/setup-buildx-action: 3.4.0/3.10.0 -> 3.11.1 - docker/build-push-action: 6.16.0 -> 6.18.0 - docker/login-action: 3.4.0 -> 3.5.0 - actions/dependency-review-action: 4.7.1 -> 4.7.3 Skipped PRs: - pyasn1 0.4.8 -> 0.6.3: blocked by mfd-powermanagement==1.12.0 pinning pyasn1==0.4.8 (no security advisories for 0.4.8) - cryptography 45.0.5 -> 46.0.5: superseded by 46.0.6 bump Addresses: #1225, #1226, #1227, #1253, #1254, #1434, #1464, #1466, #1469, #1471 Signed-off-by: Kasiewicz, Marek <marek.kasiewicz@intel.com>
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps actions/dependency-review-action from 4.7.1 to 4.7.3.
Release notes
Sourced from actions/dependency-review-action's releases.
Commits
595b5aeUpdate package version (#975)fc5fd66Claire153/fix spamming mentioned issue (#974)d38d1a4Merge pull request #965 from actions/dependabot/npm_and_yarn/multi-c22e25d29b8d420b8Merge branch 'main' into dependabot/npm_and_yarn/multi-c22e25d29bbde0129Merge pull request #966 from actions/ashelytc/add-permissionsab52490remove rubyef00a0aadd permissions to workflows74c8179Bump brace-expansionbc41886Cut 4.7.2 version release (#964)1c73553Merge pull request #960 from ahpook/ahpook/address-docs-dashesYou can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)