Skip to content

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Oct 6, 2023

Bumps gradle/gradle-build-action from 2.8.0 to 2.9.0.

Release notes

Sourced from gradle/gradle-build-action's releases.

v2.9.0

The GitHub dependency-review-action helps you understand dependency changes (and the security impact of these changes) for a pull request. This release updates the GItHub Dependency Graph support to be compatible with the dependency-review-action.

See the documentation for detailed examples.

Changelog

  • [FIX] Use correct SHA for pull-request events #882
  • [FIX] Avoid generating dependency graph during cache cleanup #905
  • [NEW] Improve warning on failure to submit dependency graph
  • [NEW] Compatibility with GitHub dependency-review-action #879

Full-changelog: gradle/gradle-build-action@v2.8.1...v2.9.0

v2.8.1

Fixes an issue that prevented Dependency Graph submission when running on GitHub Enterprise Server.

Fixes

  • Incorrect endpoint used to submit Dependency Graph on GitHub Enterprise #885

Changelog

gradle/gradle-build-action@v2.8.0...v2.8.1

Commits
  • 842c587 Merge pull request #911 - Improve dependency review support
  • 4241e05 Document configuration for dependency-review-action
  • bfa3c05 Build outputs
  • c3bdce8 Warn on dependency-graph-submit failure
  • f92e7c3 Improve compat with dependency-review-action
  • d1b726d Do not generate dependency graph in cache-cleanup
  • 6fcc109 Dependency updates (#904)
  • fde5b4f fix README.md internal references
  • 324fbdc Update to dep-graph plugin 0.4.1
  • 5658338 Build outputs
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Bumps [gradle/gradle-build-action](https://github.com/gradle/gradle-build-action) from 2.8.0 to 2.9.0. - [Release notes](https://github.com/gradle/gradle-build-action/releases) - [Commits](gradle/gradle-build-action@v2.8.0...v2.9.0) --- updated-dependencies: - dependency-name: gradle/gradle-build-action dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 6, 2023
@hauner hauner merged commit 5f2f3b5 into master Oct 8, 2023
@dependabot dependabot bot deleted the dependabot/github_actions/gradle/gradle-build-action-2.9.0 branch October 8, 2023 09:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

1 participant