Bumps gradle/gradle-build-action from 2.8.1 to 2.9.0.
Release notes
Sourced from gradle/gradle-build-action's releases.
v2.9.0
The GitHub dependency-review-action helps you understand dependency changes (and the security impact of these changes) for a pull request. This release updates the GItHub Dependency Graph support to be compatible with the
dependency-review-action.See the documentation for detailed examples.
Changelog
- [FIX] Use correct SHA for
pull-requestevents #882- [FIX] Avoid generating dependency graph during cache cleanup #905
- [NEW] Improve warning on failure to submit dependency graph
- [NEW] Compatibility with GitHub
dependency-review-action#879Full-changelog: https://github.com/gradle/gradle-build-action/compare/v2.8.1...v2.9.0
Commits
842c587Merge pull request #911 - Improve dependency review support4241e05Document configuration for dependency-review-actionbfa3c05Build outputsc3bdce8Warn on dependency-graph-submit failuref92e7c3Improve compat with dependency-review-actiond1b726dDo not generate dependency graph in cache-cleanup6fcc109Dependency updates (#904)fde5b4ffix README.md internal references324fbdcUpdate to dep-graph plugin 0.4.15658338Build outputs- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show
Comment From: dependabot[bot]
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.
If you change your mind, just re-open this PR and I'll resolve any conflicts on it.