Skip to content

chore(deps): bump actions/dependency-review-action from 4.9.0 to 5.0.0#641

Open
dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/github_actions/actions/dependency-review-action-5.0.0
Open

chore(deps): bump actions/dependency-review-action from 4.9.0 to 5.0.0#641
dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/github_actions/actions/dependency-review-action-5.0.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 19, 2026

Bumps actions/dependency-review-action from 4.9.0 to 5.0.0.

Release notes

Sourced from actions/dependency-review-action's releases.

5.0.0

This is a new major version of the Dependency Review Action which updates the runtime to node24. This requires a minimum Actions Runner version v2.327.1 to run.

What's Changed

New Contributors

Full Changelog: actions/dependency-review-action@v4.9.0...v5.0.0

Commits
  • a1d282b Merge pull request #1098 from actions/ahpook/v5-release
  • eb6c199 update examples to show @​v5
  • 3943c2c v5.0.0 release branch
  • 454943c Merge pull request #1094 from actions/ashelytc/security-findings
  • 6d92a12 revert @​typescript-eslint/parser update
  • a8e5a7e Merge pull request #1076 from tspascoal/fix-version-matching-for-non-string-s...
  • b6b7079 update @​typescript-eslint/parser to 8.40.0
  • 821a21d update more dependencies
  • 05aaaae run npm audit fix
  • 55d3e75 Merge pull request #1077 from Marukome0743/docs/checkout
  • Additional commits viewable in compare view

@dependabot dependabot Bot added ci dependencies Pull requests that update a dependency file labels May 19, 2026
@dependabot dependabot Bot requested a review from nash87 as a code owner May 19, 2026 03:21
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ci labels May 19, 2026
@github-actions github-actions Bot removed the dependencies Pull requests that update a dependency file label May 19, 2026
nash87 added a commit that referenced this pull request May 19, 2026
…post-#650 main) (#653)

Supersedes #647. Rebased onto post-#650 main; allocator + clippy +
lockfile commits dropped as no-ops (they landed via #650 + #648). Clean
diff = 2 files = bridge workflow + Gitea mirror.

Mirrors parkhub-php PR #511. Unblocks the 5 stuck parkhub-rust
Dependabot PRs (#638/#639/#640/#641/#642) once merged.

Pushed via HTTPS (parkhub-rust SSH instability documented in memory
feedback_parkhub_session_2026_05_19_operational_patterns.md).

Co-authored-by: Elly <7864054+nash87@users.noreply.github.com>
@nash87
Copy link
Copy Markdown
Owner

nash87 commented May 19, 2026

@dependabot rebase

Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action) from 4.9.0 to 5.0.0.
- [Release notes](https://github.com/actions/dependency-review-action/releases)
- [Commits](actions/dependency-review-action@2031cfc...a1d282b)

---
updated-dependencies:
- dependency-name: actions/dependency-review-action
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/github_actions/actions/dependency-review-action-5.0.0 branch from 37add08 to a0bf489 Compare May 19, 2026 12:48
@nash87 nash87 enabled auto-merge (squash) May 21, 2026 02:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant