Bump dependabot/fetch-metadata from 2.5.0 to 3.1.0 - #89
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata) from 2.5.0 to 3.1.0. - [Release notes](https://github.com/dependabot/fetch-metadata/releases) - [Commits](dependabot/fetch-metadata@v2.5.0...v3.1.0) --- updated-dependencies: - dependency-name: dependabot/fetch-metadata dependency-version: 3.1.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
@dependabot[bot] 🤖 Automatic review of commit SummaryThis change bumps the Findings : 0 Blocker · 1 Major · 1 Minor Findings1. [Major] Major-version bump of an action whose outputs are consumed downstream, with no evidence of breaking-change review
2. [Minor] Third-party action referenced by mutable tag rather than commit SHA in a workflow that holds a write-capable token
What I checked, and what I could notChecked, by reading the diff:
Not performed, and why:
Out of scope (pre-existing, not touched by this diff): the workflow's overall auto-merge policy, its The next pass will start from the next commit pushed to this branch. No rule files were found in this repository, so this review used general engineering practice. |
|
@dependabot[bot] 🤖 Automatic review of commit SummaryThis PR bumps the Findings count : 0 Blocker · 1 Major · 1 Minor Findings1. [Major] Major-version bump of
|
Bumps dependabot/fetch-metadata from 2.5.0 to 3.1.0.
Release notes
Sourced from dependabot/fetch-metadata's releases.
... (truncated)
Commits
25dd0e3v3.1.0 (#692)e073f50Merge pull request #705 from dependabot/dependabot/npm_and_yarn/hono-4.12.140670e16build(deps-dev): bump hono from 4.12.12 to 4.12.147a7fe10Merge pull request #702 from dependabot/dependabot/npm_and_yarn/dependencies-...5168191Updating dist build23882e1build(deps): bump@actions/githubin the dependencies group1072469Merge pull request #701 from dependabot/dependabot/github_actions/actions/cre...43f8a00build(deps): bump actions/create-github-app-token from 3.0.0 to 3.1.1b4d904aMerge pull request #703 from dependabot/dependabot/npm_and_yarn/globals-17.5.0c8046bbbuild(deps-dev): bump globals from 17.4.0 to 17.5.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)