Stirling-PDF/.github/workflows
dependabot[bot] 460de57900
build(deps): bump actions/dependency-review-action from 4.8.1 to 4.8.2 (#4932)
Bumps
[actions/dependency-review-action](https://github.com/actions/dependency-review-action)
from 4.8.1 to 4.8.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/dependency-review-action/releases">actions/dependency-review-action's
releases</a>.</em></p>
<blockquote>
<h2>v4.8.2</h2>
<p>Minor fixes:</p>
<ul>
<li>Fix PURL parsing for scoped packages (<a
href="https://redirect.github.com/actions/dependency-review-action/issues/1008">#1008</a>
from <a
href="https://github.com/danielhardej"><code>@​danielhardej</code></a>)</li>
<li>Fix for large summaries (<a
href="https://redirect.github.com/actions/dependency-review-action/issues/1007">#1007</a>
from <a
href="https://github.com/gitulisca"><code>@​gitulisca</code></a>)</li>
<li>README includes a working example for allow-dependencies-licenses
(<a
href="https://redirect.github.com/actions/dependency-review-action/issues/1009">#1009</a>
from <a
href="https://github.com/danielhardej"><code>@​danielhardej</code></a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="3c4e3dcb1a"><code>3c4e3dc</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/dependency-review-action/issues/1016">#1016</a>
from actions/dra-release</li>
<li><a
href="02930b2072"><code>02930b2</code></a>
Update CONTRIBUTING to reflect new guidelines</li>
<li><a
href="49ffd9f636"><code>49ffd9f</code></a>
Update CONTRIBUTING to reflect the need to build</li>
<li><a
href="70cb25ec56"><code>70cb25e</code></a>
4.8.2 release</li>
<li><a
href="ebabd31cea"><code>ebabd31</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/dependency-review-action/issues/1008">#1008</a>
from danielhardej/danielhardej-patch-20251023</li>
<li><a
href="19f9360983"><code>19f9360</code></a>
Update package-lock.json</li>
<li><a
href="5fd2f98b4f"><code>5fd2f98</code></a>
Bump <code>@​types/jest</code> to version 29.5.14</li>
<li><a
href="28647f4804"><code>28647f4</code></a>
Fix PURL parsing by removing encodeURI</li>
<li><a
href="f620fd175c"><code>f620fd1</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/dependency-review-action/issues/1013">#1013</a>
from actions/dangoor/token-fix</li>
<li><a
href="9b42b7e9a9"><code>9b42b7e</code></a>
Remove bad token reference</li>
<li>Additional commits viewable in <a
href="40c09b7dc9...3c4e3dcb1a">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/dependency-review-action&package-manager=github_actions&previous-version=4.8.1&new-version=4.8.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-11-17 23:49:43 +00:00
..
ai_pr_title_review.yml build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4931) 2025-11-17 23:49:22 +00:00
auto-labelerV2.yml build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4931) 2025-11-17 23:49:22 +00:00
build.yml build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4931) 2025-11-17 23:49:22 +00:00
check_properties.yml build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4931) 2025-11-17 23:49:22 +00:00
codeql.yml-disabled Bump: Harden Runner from v2.10.2 to v2.10.3 (#2686) 2025-01-13 22:26:05 +00:00
dependency-review.yml build(deps): bump actions/dependency-review-action from 4.8.1 to 4.8.2 (#4932) 2025-11-17 23:49:43 +00:00
licenses-update.yml build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4931) 2025-11-17 23:49:22 +00:00
manage-label.yml build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4931) 2025-11-17 23:49:22 +00:00
multiOSReleases.yml build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4931) 2025-11-17 23:49:22 +00:00
PR-Demo-cleanup.yml build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4931) 2025-11-17 23:49:22 +00:00
PR-Demo-Comment-with-react.yml build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4931) 2025-11-17 23:49:22 +00:00
pre_commit.yml build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4931) 2025-11-17 23:49:22 +00:00
push-docker.yml build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4931) 2025-11-17 23:49:22 +00:00
releaseArtifacts.yml build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4931) 2025-11-17 23:49:22 +00:00
scorecards.yml build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4931) 2025-11-17 23:49:22 +00:00
stale.yml build(deps): bump step-security/harden-runner from 2.13.1 to 2.13.2 (#4853) 2025-11-10 15:03:46 +00:00
swagger.yml build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4931) 2025-11-17 23:49:22 +00:00
sync_files.yml build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4931) 2025-11-17 23:49:22 +00:00
testdriver.yml build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4931) 2025-11-17 23:49:22 +00:00