action-allowlist-review: bump nwtgck/actions-netlify from 3.0.0 to 4.0.0 in /.github/actions/for-dependabot-triggered-reviews#915
Conversation
|
@dependabot rebase |
Bumps [nwtgck/actions-netlify](https://github.com/nwtgck/actions-netlify) from 3.0.0 to 4.0.0. - [Release notes](https://github.com/nwtgck/actions-netlify/releases) - [Changelog](https://github.com/nwtgck/actions-netlify/blob/develop/CHANGELOG.md) - [Commits](nwtgck/actions-netlify@4cbaf4c...d22a32a) --- updated-dependencies: - dependency-name: nwtgck/actions-netlify dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
7d3e847 to
c455aa7
Compare
|
The
So we can't tie the shipped bundle back to the reviewed source. I've filed nwtgck/actions-netlify#1242 upstream asking for a reproducible Not merging for now. @dfoulks1 @ppkarwasz — do you think we hold this until upstream resolves #1242, or is there a path you'd prefer (e.g. pin back / drop the entry)? Opinions welcome. |
|
The The committed This may be benign (minifier/toolchain differences) or not — it needs a human to inspect the published-vs-rebuilt diff and the in-tree binaries before this can be approved. Flagging rather than merging. |
Bumps nwtgck/actions-netlify from 3.0.0 to 4.0.0.
Release notes
Sourced from nwtgck/actions-netlify's releases.
Changelog
Sourced from nwtgck/actions-netlify's changelog.
... (truncated)
Commits
d22a32aMerge branch 'release/4.0.0'6c4be64bump: 4.0.0ea1587achore: node242f7daf7deps: updatef242d4cBuild(deps): bump undici from 5.28.3 to 5.28.4 (#1156)3bde29cBuild(deps): bump nwtgck/actions-comment-run from 2.0 to 3.0 (#1152)c71a094Merge tag 'v3.0.0' into develop