Skip to content

ci(deps): bump actions/dependency-review-action from 4.5.0 to 4.9.0 in the security-actions group across 1 directory#796

Merged
github-actions[bot] merged 1 commit intomainfrom
dependabot/github_actions/main/security-actions-33179f41c4
Mar 31, 2026
Merged

ci(deps): bump actions/dependency-review-action from 4.5.0 to 4.9.0 in the security-actions group across 1 directory#796
github-actions[bot] merged 1 commit intomainfrom
dependabot/github_actions/main/security-actions-33179f41c4

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 31, 2026

Bumps the security-actions group with 1 update in the / directory: actions/dependency-review-action.

Updates actions/dependency-review-action from 4.5.0 to 4.9.0

Release notes

Sourced from actions/dependency-review-action's releases.

Dependency Review Action 4.9.0

This feature release contains a couple of notable changes:

  • There is a new configuration option show_patched_versions which will add a column to the output, showing the fix version of each vulnerable dependency. Thanks @​felickz!
  • Runs which do not display OpenSSF scorecards no longer fetch scorecard information; previously it was fetched regardless of whether or not it was displayed, causing unneccessary slowness. Great catch @​jantiebot!
  • There are a couple of fixes to purl parsing which should improve match accuracy for allow-package-dependency lists, including case (in)sensitivity and url-encoded namespaces Thanks @​juxtin!

What's Changed

New Contributors

Full Changelog: actions/dependency-review-action@v4.8.3...v4.9.0

4.8.3

Dependency Review Action v4.8.3

This is a bugfix release that updates a number of upstream dependencies and includes a fix for the earlier feature that detected oversized summaries and upload them as artifacts, which could occasionally crash the action.

We have also updated the release process to use a long-lived v4 branch for the action, instead of a force-pushed tag, which aligns better with git branching strategies; the change should be transparent to end users.

What's Changed

Full Changelog: https://github.com/actions/dependency-review-action/compare/v4.8.2..v4.8.3

v4.8.2

Minor fixes:

... (truncated)

Commits
  • 2031cfc Merge pull request #1064 from actions/ahpook/release-4.9.0
  • d02fa39 Updates for release 4.9.0
  • 4038a34 Merge pull request #1021 from actions/dependabot/github_actions/actions/check...
  • a632b83 Merge pull request #1058 from actions/dependabot/github_actions/actions/stale...
  • 57a3d46 Merge pull request #1060 from jantiebot/main
  • 5ecdc4b Merge pull request #1045 from forks-felickz/main
  • e8c2f9a fix: remove inferrable type annotation to pass eslint
  • 0e129e1 Prettier - Refactor summary table rendering for improved readability
  • aa60746 Add 'show-patched-versions' option to configuration and update summary handling
  • e404798 Merge upstream actions/dependency-review-action main
  • Additional commits viewable in compare view

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot bot commented on behalf of github Mar 31, 2026

Labels

The following labels could not be found: automated, ci-cd, github-actions. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot bot requested a review from alienx5499 as a code owner March 31, 2026 10:08
@vercel
Copy link
Copy Markdown

vercel bot commented Mar 31, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
sortvision Ready Ready Preview, Comment Mar 31, 2026 10:13am

@github-actions
Copy link
Copy Markdown

github-actions bot commented Mar 31, 2026

QA suite report

Metric Value
Total tests 659
Passed 659
Failed 0
Warnings 0
Pass rate 100.0%
Grade S+
Duration 4.38s

Result: passed.

View workflow run

QA vs main (last successful CI on base branch)

Baseline: last green Continuous integration on main @ 077424d (same test:ci suite).

Base This PR Δ passed
Passed 659 659 0
Failed 0 0
Total 659 659

Fixed (failed on base, passing on this PR)

None

New failures (failed on this PR; were not failing on base)

None

Still failing (failed on base and still failing on this PR)

None

@github-actions
Copy link
Copy Markdown

github-actions bot commented Mar 31, 2026

Lighthouse (CI)

View workflow run

Lighthouse vs main (last green CI on base)

Lighthouse (mobile)

Δ = change vs last successful Continuous integration on main (same URLs).

URL Perf Δ A11y Δ Best Δ SEO Δ
http://localhost:3000/ 70 +20 96 93 100
http://localhost:3000/algorithms/config/bubble 76 -1 96 93 100
http://localhost:3000/es 77 +1 96 93 100
http://localhost:3000/contributions/overview 68 96 96 100

Lighthouse (desktop)

Δ = change vs last successful Continuous integration on main (same URLs).

URL Perf Δ A11y Δ Best Δ SEO Δ
http://localhost:3000/ 97 -2 96 96 100
http://localhost:3000/algorithms/config/bubble 98 +1 96 96 100
http://localhost:3000/es 98 +1 96 96 100
http://localhost:3000/contributions/overview 98 +1 96 96 100

@github-actions
Copy link
Copy Markdown

Dependabot auto-merge

Could not enable auto-merge after Continuous integration succeeded.

Common causes: auto-merge disabled in repo settings, branch protection (reviews / code owners), merge queue rules, or token permissions.

CLI output:

GraphQL: Pull request Protected branch rules not configured for this branch (enablePullRequestAutoMerge)

Bumps the security-actions group with 1 update: [actions/dependency-review-action](https://github.com/actions/dependency-review-action).


Updates `actions/dependency-review-action` from 4.5.0 to 4.9.0
- [Release notes](https://github.com/actions/dependency-review-action/releases)
- [Commits](actions/dependency-review-action@3b139cf...2031cfc)

---
updated-dependencies:
- dependency-name: actions/dependency-review-action
  dependency-version: 4.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: security-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot changed the title ci(deps): bump actions/dependency-review-action from 4.5.0 to 4.9.0 in the security-actions group ci(deps): bump actions/dependency-review-action from 4.5.0 to 4.9.0 in the security-actions group across 1 directory Mar 31, 2026
@dependabot dependabot bot force-pushed the dependabot/github_actions/main/security-actions-33179f41c4 branch from 740ed26 to c2721b9 Compare March 31, 2026 10:12
@github-actions github-actions bot merged commit 218e792 into main Mar 31, 2026
12 checks passed
@github-actions
Copy link
Copy Markdown

Dependabot auto-merge

Auto-merge is enabled (squash). GitHub will merge this PR once all required checks and reviews pass.

@dependabot dependabot bot deleted the dependabot/github_actions/main/security-actions-33179f41c4 branch March 31, 2026 10:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants