[release/v7.5.6] Bump actions/dependency-review-action from 4.8.3 to 4.9.0 by adityapatwardhan · Pull Request #27158 · PowerShell/PowerShell · GitHub
Skip to content

[release/v7.5.6] Bump actions/dependency-review-action from 4.8.3 to 4.9.0#27158

Merged
adityapatwardhan merged 1 commit intoPowerShell:release/v7.5.6from
adityapatwardhan:backport/release/v7.5.6/26938-1ee3d7116
Apr 3, 2026
Merged

[release/v7.5.6] Bump actions/dependency-review-action from 4.8.3 to 4.9.0#27158
adityapatwardhan merged 1 commit intoPowerShell:release/v7.5.6from
adityapatwardhan:backport/release/v7.5.6/26938-1ee3d7116

Conversation

@adityapatwardhan
Copy link
Copy Markdown
Member

Backport of #26938 to release/v7.5.6

Triggered by @adityapatwardhan on behalf of @app/dependabot

Original CL Label: CL-BuildPackaging

/cc @PowerShell/powershell-maintainers

Impact

REQUIRED: Choose either Tooling Impact or Customer Impact (or both). At least one checkbox must be selected.

Tooling Impact

  • Required tooling change
  • Optional tooling change (include reasoning)

Updates the pinned GitHub Actions dependency review action on the release branch to keep CI security tooling current.

Customer Impact

  • Customer reported
  • Found internally

Regression

REQUIRED: Check exactly one box.

  • Yes
  • No

This is not a regression.

Testing

Verified the cherry-picked workflow change only updates actions/dependency-review-action pin in .github/workflows/dependency-review.yml and preserves release/v7.5.6-specific checkout pin. Cherry-pick completed cleanly after resolving one workflow-line conflict.

Risk

REQUIRED: Check exactly one box.

  • High
  • Medium
  • Low

Single-line workflow action version bump in CI/security tooling; scoped change with no product runtime impact.

Merge Conflicts

Conflict in .github/workflows/dependency-review.yml on the dependency-review-action pin due branch drift. Resolved by keeping release/v7.5.6 checkout pin and applying the intended dependency-review-action@2031cfc080254a8a887f58cffee85186f0e49e48 update.

@adityapatwardhan adityapatwardhan added the CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log label Apr 2, 2026
Copilot AI review requested due to automatic review settings April 2, 2026 20:37
@adityapatwardhan adityapatwardhan requested a review from a team as a code owner April 2, 2026 20:37
@adityapatwardhan adityapatwardhan added the CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log label Apr 2, 2026
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports the GitHub Actions security tooling update to the release/v7.5.6 branch by updating the pinned actions/dependency-review-action revision used in the Dependency Review workflow.

Changes:

  • Bump actions/dependency-review-action pin to the commit for v4.9.0 in .github/workflows/dependency-review.yml.

Comment on lines 21 to +22
Copy link

Copilot AI Apr 2, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PR title/description says this is a bump from v4.8.3 → v4.9.0, but the workflow previously pinned actions/dependency-review-action at v4.3.4 (per the removed line in this diff). Please update the PR title/description to reflect the actual from-version for this release branch, or add a note explaining the difference from the original PR.

Copilot uses AI. Check for mistakes.
@adityapatwardhan adityapatwardhan merged commit 2e90a92 into PowerShell:release/v7.5.6 Apr 3, 2026
41 checks passed
@adityapatwardhan adityapatwardhan deleted the backport/release/v7.5.6/26938-1ee3d7116 branch April 3, 2026 00:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants