Skip to content

Comments

Bump actions/dependency-review-action from 68e9887ce6c0bf076e739ad56332b1ee8bc7f88c to dea54b434272cc45b0e9ff17d5f0da4d8676f07d#195

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/github_actions/actions/dependency-review-action-dea54b434272cc45b0e9ff17d5f0da4d8676f07d
Open

Bump actions/dependency-review-action from 68e9887ce6c0bf076e739ad56332b1ee8bc7f88c to dea54b434272cc45b0e9ff17d5f0da4d8676f07d#195
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/github_actions/actions/dependency-review-action-dea54b434272cc45b0e9ff17d5f0da4d8676f07d

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 22, 2026

Bumps actions/dependency-review-action from 68e9887ce6c0bf076e739ad56332b1ee8bc7f88c to dea54b434272cc45b0e9ff17d5f0da4d8676f07d.

Commits
  • dea54b4 Merge pull request #1057 from actions/juxtin/case-sensitivity
  • 8cf743c Make purl comparisons case insensitive
  • b49f407 Merge pull request #1056 from actions/juxtin/fix-exclusion-match
  • f68b94a Merge remote-tracking branch 'origin/main' into juxtin/fix-exclusion-match
  • 05fe457 Merge pull request #1054 from actions/ahpook/release-4.8.3
  • 2ced98c Compare normalized purls to account for encoding quirks
  • 3a8496c Update generated package files for v4.8.3
  • 0f22a01 Update CONTRIBUTING for new release process
  • 58be343 Updating package versions for 4.8.3
  • 9284e0c Merge pull request #931 from actions/dependabot/npm_and_yarn/spdx-licenses-20...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action) from 68e9887ce6c0bf076e739ad56332b1ee8bc7f88c to dea54b434272cc45b0e9ff17d5f0da4d8676f07d.
- [Release notes](https://github.com/actions/dependency-review-action/releases)
- [Commits](actions/dependency-review-action@68e9887...dea54b4)

---
updated-dependencies:
- dependency-name: actions/dependency-review-action
  dependency-version: dea54b434272cc45b0e9ff17d5f0da4d8676f07d
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Feb 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant