20
20
- name : ' Checkout Repository'
21
21
uses : actions/checkout@v4
22
22
- name : ' Dependency Review'
23
- uses : actions/dependency-review-action@v3
23
+ uses : actions/dependency-review-action@v4
24
24
` ` `
25
25
26
26
## Using an inline configuration
41
41
- name : ' Checkout Repository'
42
42
uses : actions/checkout@v4
43
43
- name : ' Dependency Review'
44
- uses : actions/dependency-review-action@v3
44
+ uses : actions/dependency-review-action@v4
45
45
with :
46
46
fail-on-severity : critical
47
47
deny-licenses : LGPL-2.0, BSD-2-Clause
78
78
- name: 'Checkout Repository'
79
79
uses: actions/checkout@v4
80
80
- name: 'Dependency Review'
81
- uses: actions/dependency-review-action@v3
81
+ uses: actions/dependency-review-action@v4
82
82
with:
83
83
config-file: './.github/dependency-review-config.yml'
84
84
` ` `
@@ -105,7 +105,7 @@ jobs:
105
105
- name: 'Checkout Repository'
106
106
uses: actions/checkout@v4
107
107
- name: 'Dependency Review'
108
- uses: actions/dependency-review-action@v3
108
+ uses: actions/dependency-review-action@v4
109
109
with:
110
110
config-file: 'github/octorepo/dependency-review-config.yml@main'
111
111
` ` `
@@ -132,7 +132,7 @@ jobs:
132
132
- name: 'Checkout Repository'
133
133
uses: actions/checkout@v4
134
134
- name: 'Dependency Review'
135
- uses: actions/dependency-review-action@v3
135
+ uses: actions/dependency-review-action@v4
136
136
with:
137
137
config-file: 'github/octorepo-private/dependency-review-config.yml@main'
138
138
external-repo-token: ${{ secrets.GITHUB_TOKEN }} # or a personal access token
@@ -157,7 +157,7 @@ jobs:
157
157
- name: 'Checkout Repository'
158
158
uses: actions/checkout@v4
159
159
- name: 'Dependency Review'
160
- uses: actions/dependency-review-action@v3
160
+ uses: actions/dependency-review-action@v4
161
161
with:
162
162
fail-on-severity: critical
163
163
deny-licenses: LGPL-2.0, BSD-2-Clause
@@ -185,7 +185,7 @@ jobs:
185
185
- name: 'Checkout Repository'
186
186
uses: actions/checkout@v4
187
187
- name: 'Dependency Review'
188
- uses: actions/dependency-review-action@v3
188
+ uses: actions/dependency-review-action@v4
189
189
with:
190
190
fail-on-severity: critical
191
191
deny-licenses: LGPL-2.0, BSD-2-Clause
@@ -224,7 +224,7 @@ jobs:
224
224
- name: 'Checkout Repository'
225
225
uses: actions/checkout@v4
226
226
- name: 'Dependency Review'
227
- uses: actions/dependency-review-action@v3
227
+ uses: actions/dependency-review-action@v4
228
228
with:
229
229
fail-on-severity: critical
230
230
comment-summary-in-pr: always
@@ -253,7 +253,7 @@ jobs:
253
253
- name: 'Checkout Repository'
254
254
uses: actions/checkout@v4
255
255
- name: 'Dependency Review'
256
- uses: actions/dependency-review-action@v3
256
+ uses: actions/dependency-review-action@v4
257
257
with:
258
258
deny-packages: 'pkg:maven/org.apache.logging.log4j/log4j-api,pkg:maven/org.apache.logging.log4j/log4j-core'
259
259
deny-groups: 'pkg:maven/com.bazaarvoice.jolt'
@@ -287,7 +287,7 @@ jobs:
287
287
- name: 'Checkout Repository'
288
288
uses: actions/checkout@v4
289
289
- name: 'Dependency Review'
290
- uses: actions/dependency-review-action@v3
290
+ uses: actions/dependency-review-action@v4
291
291
with:
292
292
retry-on-snapshot-warnings: true
293
293
retry-on-snapshot-warnings-timeout: 60
0 commit comments