Dependabot alerts should support conventional major version tags with GitHub Actions #54553
-
Select Topic AreaBug BodyIt is conventional (and indeed recommended) to use a major version tag to track the latest version of a GitHub Action release. For example, actions/cache@v3 and actions/cache@v3.3.1 are currently identical (point to the same commit). With each new release in the v3.x stream, the We recently published a security advisory for Unfortunately, all repositories referencing the major version tag received a Dependabot alert for this vulnerability, and the only options to resolve this are:
Interestingly, Dependabot does detect that no upgrade is required, but fails to dismiss the alert as "fixed". |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
Update - we have resolved this! :) |
Beta Was this translation helpful? Give feedback.
Update - we have resolved this! :)