Skip to content

Bump the github-actions group with 2 updates - #683

Merged
webstackdev merged 2 commits into
mainfrom
dependabot/github_actions/github-actions-6c5e1d7dfc
May 14, 2026
Merged

webstackdev merged 2 commits into
mainfrom
dependabot/github_actions/github-actions-6c5e1d7dfc

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 14, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 2 updates: actions/dependency-review-action and davelosert/vitest-coverage-report-action.

Updates actions/dependency-review-action from 4.9.0 to 5.0.0

Release notes

Sourced from actions/dependency-review-action's releases.

5.0.0

This is a new major version of the Dependency Review Action which updates the runtime to node24. This requires a minimum Actions Runner version v2.327.1 to run.

What's Changed

New Contributors

Full Changelog: actions/dependency-review-action@v4.9.0...v5.0.0

Commits
  • a1d282b Merge pull request #1098 from actions/ahpook/v5-release
  • eb6c199 update examples to show @​v5
  • 3943c2c v5.0.0 release branch
  • 454943c Merge pull request #1094 from actions/ashelytc/security-findings
  • 6d92a12 revert @​typescript-eslint/parser update
  • a8e5a7e Merge pull request #1076 from tspascoal/fix-version-matching-for-non-string-s...
  • b6b7079 update @​typescript-eslint/parser to 8.40.0
  • 821a21d update more dependencies
  • 05aaaae run npm audit fix
  • 55d3e75 Merge pull request #1077 from Marukome0743/docs/checkout
  • Additional commits viewable in compare view

Updates davelosert/vitest-coverage-report-action from 2.11.2 to 2.12.0

Release notes

Sourced from davelosert/vitest-coverage-report-action's releases.

v2.12.0

2.12.0 (2026-05-12)

Features

  • add sort-by option to order files by coverage (#620) (b19e5be), closes #617
Commits
  • 02f3c2e chore(deps-dev): bump @​biomejs/biome from 2.4.14 to 2.4.15 (#627)
  • 6f44a68 chore(deps-dev): bump the build-deps group across 1 directory with 5 updates ...
  • 7c3b492 chore(deps-dev): bump @​semantic-release/github (#626)
  • b19e5be feat: add sort-by option to order files by coverage (#620)
  • 9083fcd chore(deps-dev): bump postcss from 8.5.8 to 8.5.12 (#624)
  • 2ec1257 chore(deps-dev): bump @​biomejs/biome from 2.4.13 to 2.4.14 (#625)
  • ed6f384 chore(deps-dev): bump @​biomejs/biome from 2.4.11 to 2.4.13 (#622)
  • 144a8fd chore(deps): bump the deps group with 2 updates (#621)
  • 5851dcb chore(deps-dev): bump @​biomejs/biome from 2.4.10 to 2.4.11 (#616)
  • 352e959 chore(deps-dev): bump the build-deps group with 4 updates (#615)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions group with 2 updates: [actions/dependency-review-action](https://github.com/actions/dependency-review-action) and [davelosert/vitest-coverage-report-action](https://github.com/davelosert/vitest-coverage-report-action).


Updates `actions/dependency-review-action` from 4.9.0 to 5.0.0
- [Release notes](https://github.com/actions/dependency-review-action/releases)
- [Commits](actions/dependency-review-action@v4.9.0...v5.0.0)

Updates `davelosert/vitest-coverage-report-action` from 2.11.2 to 2.12.0
- [Release notes](https://github.com/davelosert/vitest-coverage-report-action/releases)
- [Changelog](https://github.com/davelosert/vitest-coverage-report-action/blob/main/release.config.js)
- [Commits](davelosert/vitest-coverage-report-action@3c50566...02f3c2e)

---
updated-dependencies:
- dependency-name: actions/dependency-review-action
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: davelosert/vitest-coverage-report-action
  dependency-version: 2.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels May 14, 2026
@github-actions

github-actions Bot commented May 14, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
actions/davelosert/vitest-coverage-report-action 02f3c2e641286b7fa308cd3e430783103ce6103b 🟢 5.6
Details
CheckScoreReason
Code-Review⚠️ 0Found 0/3 approved changesets -- score normalized to 0
Maintained🟢 1030 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Security-Policy🟢 10security policy file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies⚠️ 1dependency not pinned by hash detected -- score normalized to 1
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Branch-Protection🟢 3branch protection is not maximal on development and all release branches
Packaging🟢 10packaging workflow detected
SAST🟢 7SAST tool detected but not run on all commits

Scanned Files

  • .github/workflows/test.yml

@github-actions

github-actions Bot commented May 14, 2026

Copy link
Copy Markdown

Coverage Report

Status Category Percentage Covered / Total
🔵 Lines 71.73% 10789 / 15041
🔵 Statements 69.66% 11363 / 16311
🔵 Functions 71.44% 2217 / 3103
🔵 Branches 55.94% 6164 / 11017
File CoverageNo changed files found.
Generated in workflow #525 for commit 11e015b by the Vitest Coverage Report Action

@github-actions

Copy link
Copy Markdown

@webstackdev
webstackdev merged commit 9d0e8d2 into main May 14, 2026
19 checks passed
@webstackdev
webstackdev deleted the dependabot/github_actions/github-actions-6c5e1d7dfc branch May 14, 2026 18:24

This branch was previously deployed

3 inactive deployments
Preview 11e015bc Deployed May 14, 2026 by github-actions[bot]
testing 11e015bc Deployed May 14, 2026 by webstackdev via Lint #437
preview 11e015bc Deployed May 14, 2026 by webstackdev via Deploy Preview #462
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file deployed github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant