Skip to content

Bump actions/dependency-review-action from 4.5.0 to 4.7.1#78

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/dependency-review-action-4.7.1
Closed

Bump actions/dependency-review-action from 4.5.0 to 4.7.1#78
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/dependency-review-action-4.7.1

Bump actions/dependency-review-action from 4.5.0 to 4.7.1

7991319
Select commit
Loading
Failed to load commit list.
This check has been archived and is scheduled for deletion. Learn more about checks retention
StepSecurity Actions Security / StepSecurity Harden-Runner succeeded May 21, 2025 in 2m 47s

No anomalous activity on CI/CD runners

No new Harden-Runner detections for this pull request.

Details

Harden-Runner monitors all outbound traffic from each job at the DNS and network layers to ensure that CI/CD runners do not communicate with unauthorized destinations.
This reduces the risk of CI/CD secrets and source code being exfiltrated.

📋 Monitored GitHub Actions workflow runs

The following GitHub Actions workflow runs were monitored as part of this pull request.

Workflow Run ID Unique Destinations Actions Used Detailed Insights
codeql.yml 15154399483 3 3 View Insights
dependency-review.yml 15154399473 3 3 View Insights
test.yaml 15154399209 2 3 View Insights
test.yaml 15154399482 2 3 View Insights

📚 Learn More

You can learn more about this GitHub check here