Skip to content

Bump advanced-security/component-detection-dependency-submission-action from 0.1.3 to 0.1.4#289

Merged
MPCoreDeveloper merged 1 commit into
masterfrom
dependabot/github_actions/advanced-security/component-detection-dependency-submission-action-0.1.4
Jul 26, 2026
Merged

Bump advanced-security/component-detection-dependency-submission-action from 0.1.3 to 0.1.4#289
MPCoreDeveloper merged 1 commit into
masterfrom
dependabot/github_actions/advanced-security/component-detection-dependency-submission-action-0.1.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 13, 2026

Copy link
Copy Markdown
Contributor

Bumps advanced-security/component-detection-dependency-submission-action from 0.1.3 to 0.1.4.

Release notes

Sourced from advanced-security/component-detection-dependency-submission-action's releases.

v0.1.4

What's Changed

New Contributors

Full Changelog: advanced-security/component-detection-dependency-submission-action@v0.1.3...v0.1.4

Commits
  • 31f25a8 Merge pull request #216 from advanced-security/copilot/fix-undici-memory-vuln...
  • 8100427 chore: rebuild dist after undici override update
  • d011523 fix: upgrade transitive undici deps to 6.27.0 via npm overrides (GHSA-vrm6-8v...
  • c24f5d6 Initial plan
  • e1dafa1 Merge pull request #214 from advanced-security/copilot/fix-undici-memory-cons...
  • ca82249 Merge pull request #213 from advanced-security/copilot/bump-npm-dependencies-...
  • 03b4282 fix: update undici to 6.27.0 via overrides to fix GHSA-vrm6-8vpv-qv8q
  • 5e9ca38 Merge pull request #210 from advanced-security/copilot/fix-undici-websocket-v...
  • d7e565b Initial plan
  • 9a1253d Initial plan
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [advanced-security/component-detection-dependency-submission-action](https://github.com/advanced-security/component-detection-dependency-submission-action) from 0.1.3 to 0.1.4.
- [Release notes](https://github.com/advanced-security/component-detection-dependency-submission-action/releases)
- [Commits](advanced-security/component-detection-dependency-submission-action@v0.1.3...v0.1.4)

---
updated-dependencies:
- dependency-name: advanced-security/component-detection-dependency-submission-action
  dependency-version: 0.1.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 13, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: github-actions. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 13, 2026
@codecov

codecov Bot commented Jul 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@MPCoreDeveloper
MPCoreDeveloper merged commit 42c2ff2 into master Jul 26, 2026
9 checks passed
@MPCoreDeveloper
MPCoreDeveloper deleted the dependabot/github_actions/advanced-security/component-detection-dependency-submission-action-0.1.4 branch July 26, 2026 12:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant