Kevin Dangoor
75e65b4d81
Generate dist files on main branch
...
This adapts an approach taken by the Gradle actions in order to
generate the dist files on the main branch rather than having
every contributor need to generate them. (In fact, people will no
longer be able to submit PRs with the dist files updated). This
change is important because the current approach means that
people encounter merge conflicts all the time and will need to
keep regenerating the dist files in order to land their change.
2025-11-05 17:30:02 -05:00
Kevin Dangoor
355d25e5a7
Merge pull request #921 from jsoref/spelling
...
Spelling
2025-11-04 18:48:20 -08:00
Josh Soref
d456baec30
spelling: vulnerabilities
...
Signed-off-by: Josh Soref <[email protected] >
2025-11-04 21:39:50 -05:00
Josh Soref
66054da10b
spelling: vuln
...
Signed-off-by: Josh Soref <[email protected] >
2025-11-04 21:39:50 -05:00
Josh Soref
247f07b0c8
spelling: summary
...
Signed-off-by: Josh Soref <[email protected] >
2025-11-04 21:39:50 -05:00
Josh Soref
5975520ad2
spelling: statement
...
Signed-off-by: Josh Soref <[email protected] >
2025-11-04 20:17:52 -05:00
Josh Soref
b4849e7628
spelling: lodash
...
Signed-off-by: Josh Soref <[email protected] >
2025-11-04 20:17:52 -05:00
Josh Soref
752c04656e
spelling: github
...
Signed-off-by: Josh Soref <[email protected] >
2025-11-04 20:17:52 -05:00
Josh Soref
4fa8b92807
Add alt text for screen to create a PAT
...
Signed-off-by: Josh Soref <[email protected] >
2025-11-04 20:17:44 -05:00
Josh Soref
3660056ed3
Add alt text for screen showing Release Action
...
Signed-off-by: Josh Soref <[email protected] >
2025-11-04 20:17:34 -05:00
Josh Soref
5f8348ab03
Add alt text for screen to create arelease
...
Signed-off-by: Josh Soref <[email protected] >
2025-11-04 20:16:44 -05:00
Josh Soref
6b5a983daf
link: full list of configuration options
...
Signed-off-by: Josh Soref <[email protected] >
2025-11-04 20:08:49 -05:00
Josh Soref
8fd9b22286
link: the configuration
...
Signed-off-by: Josh Soref <[email protected] >
2025-11-04 20:08:49 -05:00
Josh Soref
c4b82d3047
Reword comment-summary-in-pr description
...
Signed-off-by: Josh Soref <[email protected] >
2025-11-04 20:08:49 -05:00
Josh Soref
622445f2a8
Remove unused import
...
Signed-off-by: Josh Soref <[email protected] >
2025-11-04 20:08:49 -05:00
Kevin Dangoor
3f464ea511
Merge pull request #1009 from danielhardej/patch-1
...
Update README to include `allow-dependencies-licenses` example
2025-11-04 14:35:46 -08:00
Lewis Jones
8e51299cdf
Merge pull request #1007 from gitulisca/gitulisca/summary-size-limit
...
Make handleLargeSummary also update core.summary
2025-10-27 12:51:46 +00:00
Art Leo
7a990117b1
Add dist files
2025-10-27 17:41:42 +11:00
Dan Hardej
99ce29f02e
Update README with allowed-dependencies-licenses example
2025-10-23 16:31:35 +08:00
gitulisca and Copilot
140b44b7bf
Remove trailing whitespace from blank line
...
Co-authored-by: Copilot <[email protected] >
2025-10-22 19:12:18 +11:00
Art Leo
4603a62e00
Make handleLargeSummary also update core.summary
2025-10-22 17:52:52 +11:00
Eric Sorenson
07b91577a3
Merge pull request #920 from jsoref/issue-919
2025-10-17 14:30:12 -07:00
Josh Soref
3084754c49
Scope warning about private repositories
2025-10-15 14:16:01 -04:00
Eric Sorenson
40c09b7dc9
Merge pull request #1001 from actions/ahpook/v4.8.1-release
v4.8.1
2025-10-10 14:06:00 -07:00
Eric Sorenson
45529485b5
Bump version for 4.8.1 release
2025-10-10 12:55:32 -07:00
Eric Sorenson
e63da9a041
Merge pull request #1000 from actions/ahpook/deprecation-redux
2025-10-10 12:21:31 -07:00
Eric Sorenson
71365c76bc
(bug) Fix spamming link test in deprecation warning (again)
...
We'd thought that the syntax in #974 would avoid auto-linking
but didn't check closely enough, and now the deprecation issue
it links to cannot be loaded due to having too many references.
This updates the text to point to a new issue in a way that...
I hope... will not be auto-linked.
2025-10-10 09:37:13 -07:00
Barry Gordon
56339e523c
Merge pull request #988 from actions/brrygrdn/rc-4.8.0
...
Bump to 4.8.0
v4.8.0
2025-09-26 16:05:17 +01:00
Barry Gordon
1688b745f3
Bump to a 4.8.0
2025-09-26 15:45:28 +01:00
Barry Gordon
31c9f175b9
Merge pull request #987 from actions/rc-4.7.4
...
Prepare release of v4.7.4
v4.7.4
2025-09-26 15:20:06 +01:00
Barry Gordon
eacde7836e
Update version
2025-09-26 14:42:22 +01:00
Barry Gordon
81510090e4
Merge pull request #986 from actions/brrygrdn/rc-4.7.4
...
Batch some contributions for release
2025-09-26 14:32:46 +01:00
Barry Gordon
b472ec914b
Add a quick regression test for the artefact summary
2025-09-26 13:34:03 +01:00
Matt Mencel
e0cedc52dc
feat: add large summary handling with artifact upload
...
When the dependency review summary exceeds GitHub's size limit (1024k), upload it as an artifact and provide a link in the comment. This ensures users can still access the full review details even when the summary is too large to display directly.
2025-09-26 12:55:14 +01:00
Jasper Kamerling
e3fdf0f899
This ensures large allow or deny lists don't create huge comments
2025-09-26 12:49:38 +01:00
Lewis Jones
6fad417932
Merge pull request #978 from actions/ljones140/make-ruby-code-scannable
...
Make Ruby Code Scannable
2025-08-29 10:39:17 +01:00
Lewis Jones and Copilot
e86e9692ad
Update scripts/scan_pr_lib.rb
...
Co-authored-by: Copilot <[email protected] >
2025-08-28 16:24:02 +01:00
Lewis Jones
85c8e53ab7
Scan ruby
2025-08-28 16:12:23 +01:00
Lewis Jones
c6a7eb7252
Extract ruby code
...
So can be scanned by code scanning
2025-08-28 16:11:56 +01:00
Claire Song
595b5aeba7
Update package version ( #975 )
v4.7.3
2025-08-26 13:00:34 -07:00
Claire Song
fc5fd661aa
Claire153/fix spamming mentioned issue ( #974 )
...
* Keep the issue number and remove the url to avoid linking every PR running the action to that issue
2025-08-26 12:46:02 -07:00
Ashely Tenesaca
d38d1a4f40
Merge pull request #965 from actions/dependabot/npm_and_yarn/multi-c22e25d29b
...
Bump brace-expansion
2025-08-20 17:40:22 -04:00
Ashely Tenesaca
8d420b827c
Merge branch 'main' into dependabot/npm_and_yarn/multi-c22e25d29b
2025-08-20 17:28:38 -04:00
Ashely Tenesaca
bde01290d3
Merge pull request #966 from actions/ashelytc/add-permissions
...
Add explicit permissions to workflow files
2025-08-20 09:33:56 -04:00
Ashely Tenesaca
ab524903e8
remove ruby
2025-08-19 17:11:41 -04:00
Ashely Tenesaca
ef00a0afbb
add permissions to workflows
2025-08-19 20:55:24 +00:00
dependabot[bot]
74c8179d39
Bump brace-expansion
...
Bumps and [brace-expansion](https://github.com/juliangruber/brace-expansion ). These dependencies needed to be updated together.
Updates `brace-expansion` from 1.1.11 to 1.1.12
- [Release notes](https://github.com/juliangruber/brace-expansion/releases )
- [Commits](https://github.com/juliangruber/brace-expansion/compare/1.1.11...v1.1.12 )
Updates `brace-expansion` from 2.0.1 to 2.0.2
- [Release notes](https://github.com/juliangruber/brace-expansion/releases )
- [Commits](https://github.com/juliangruber/brace-expansion/compare/1.1.11...v1.1.12 )
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 1.1.12
dependency-type: indirect
- dependency-name: brace-expansion
dependency-version: 2.0.2
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <[email protected] >
2025-08-18 22:33:26 +00:00
Claire Song
bc41886e18
Cut 4.7.2 version release ( #964 )
...
* Cut 4.7.2 version release
* Bump dependency minor versions
v4.7.2
2025-08-18 11:17:54 -07:00
Kevin Dangoor
1c73553e36
Merge pull request #960 from ahpook/ahpook/address-docs-dashes
...
Address discrepancy between docs and reality
2025-08-18 14:02:19 -04:00
dependabot[bot] and dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
fac3d41a58
Bump the minor-updates group across 1 directory with 5 updates ( #956 )
...
Bumps the minor-updates group with 5 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [ts-jest](https://github.com/kulshekhar/ts-jest ) | `29.4.0` | `29.4.1` |
| [yaml](https://github.com/eemeli/yaml ) | `2.8.0` | `2.8.1` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node ) | `20.19.7` | `20.19.10` |
| [eslint-plugin-prettier](https://github.com/prettier/eslint-plugin-prettier ) | `5.5.1` | `5.5.4` |
| [typescript](https://github.com/microsoft/TypeScript ) | `5.8.3` | `5.9.2` |
Updates `ts-jest` from 29.4.0 to 29.4.1
- [Release notes](https://github.com/kulshekhar/ts-jest/releases )
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md )
- [Commits](https://github.com/kulshekhar/ts-jest/compare/v29.4.0...v29.4.1 )
Updates `yaml` from 2.8.0 to 2.8.1
- [Release notes](https://github.com/eemeli/yaml/releases )
- [Commits](https://github.com/eemeli/yaml/compare/v2.8.0...v2.8.1 )
Updates `@types/node` from 20.19.7 to 20.19.10
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node )
Updates `eslint-plugin-prettier` from 5.5.1 to 5.5.4
- [Release notes](https://github.com/prettier/eslint-plugin-prettier/releases )
- [Changelog](https://github.com/prettier/eslint-plugin-prettier/blob/main/CHANGELOG.md )
- [Commits](https://github.com/prettier/eslint-plugin-prettier/compare/v5.5.1...v5.5.4 )
Updates `typescript` from 5.8.3 to 5.9.2
- [Release notes](https://github.com/microsoft/TypeScript/releases )
- [Changelog](https://github.com/microsoft/TypeScript/blob/main/azure-pipelines.release-publish.yml )
- [Commits](https://github.com/microsoft/TypeScript/compare/v5.8.3...v5.9.2 )
---
updated-dependencies:
- dependency-name: ts-jest
dependency-version: 29.4.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-updates
- dependency-name: yaml
dependency-version: 2.8.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-updates
- dependency-name: "@types/node"
dependency-version: 20.19.10
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: minor-updates
- dependency-name: eslint-plugin-prettier
dependency-version: 5.5.4
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: minor-updates
- dependency-name: typescript
dependency-version: 5.9.2
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: minor-updates
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-08-18 10:31:31 -07:00