Bumps gradle/gradle-build-action from 2.9.0 to 2.10.0.
Release notes
Sourced from gradle/gradle-build-action's releases.
v2.10.0
This release introduces a new
artifact-retention-daysparameter, which allows a user to configure how long the generated dependency-graph artifacts are retained by GitHub Actions. Adjusting the retention period can be useful to reduce storage costs associated with these dependency-graph artifacts.See the documentation for more details.
Changelog
- [NEW] Add
artifact-retention-daysconfiguration parameter #903- [FIX] Update to
v1.0.0of the github-dependency-graph-gradle-plugin- [FIX] Update
@babel/traverseto address reported security vulnerabilityFull-changelog: https://github.com/gradle/gradle-build-action/compare/v2.9.0...v2.10.0
Commits
87a9a15Use 1.0.0 release of dependency graph plugin3754817Documentartifact-retention-daysbeff1c5Update dev dependencies21a3ebbBump com.fasterxml.jackson.dataformat:jackson-dataformat-smilea5be560Bump the github-actions group with 2 updates9bca466Make artifact retention configurablef757bcfMerge pull request #951 from gradle/dd/v2.9.18b6c211Bump to RC of github dependency graph plugin8db1c76Build outputs6eaacfcUpdate NPM dependencies- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show
Comment From: dependabot[bot]
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.
If you change your mind, just re-open this PR and I'll resolve any conflicts on it.