From 69ee15f5c1bc9a07ebb02fc5c44032f274b2bf9c Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 23 Feb 2026 23:02:01 +0000 Subject: [PATCH] chore(deps): bump actions/dependency-review-action Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action) from 4.8.2 to 4.8.3. - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](https://github.com/actions/dependency-review-action/compare/3c4e3dcb1aa7874d2c16be7d79418e9b7efd6261...05fe4576374b728f0c523d6a13d64c25081e0803) --- updated-dependencies: - dependency-name: actions/dependency-review-action dependency-version: 4.8.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- workflow-templates/dependency-review.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/workflow-templates/dependency-review.yaml b/workflow-templates/dependency-review.yaml index f362ab3e..8f7127d7 100644 --- a/workflow-templates/dependency-review.yaml +++ b/workflow-templates/dependency-review.yaml @@ -22,7 +22,7 @@ jobs: run: echo "first_commit_sha=$(git rev-list --max-parents=0 HEAD)" >> $GITHUB_ENV - name: 'Dependency Review (manual)' if: github.event_name == 'workflow_dispatch' - uses: actions/dependency-review-action@3c4e3dcb1aa7874d2c16be7d79418e9b7efd6261 # v4.8.2 + uses: actions/dependency-review-action@05fe4576374b728f0c523d6a13d64c25081e0803 # v4.8.3 with: base-ref: ${{ env.first_commit_sha }} head-ref: ${{ github.ref }} @@ -32,7 +32,7 @@ jobs: warn-only: true - name: 'Dependency Review (pull_request)' if: github.event_name == 'pull_request' - uses: actions/dependency-review-action@3c4e3dcb1aa7874d2c16be7d79418e9b7efd6261 # v4.8.2 + uses: actions/dependency-review-action@05fe4576374b728f0c523d6a13d64c25081e0803 # v4.8.3 with: show-openssf-scorecard: true vulnerability-check: true