New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
v4.3.0 Causing PURL Processing Errors #752
Comments
Was just about to report the same issue. Had to pin to Edit: I get a slightly different error with v4.3 is |
Thanks for the report, @watercable76! Sorry for the bother, I've reset the |
I'm having a hard time reproducing this in my test repo(s). @watercable76, can you share (a possibly redacted version of) your dependency review config? |
I've narrowed down the cause of this to the handling of Nonetheless, I've seen many implementations that tolerate Given the amount of monkeying around we've already had to do to get this library working, and our modest needs for parsing in the first place, I'm tempted to just hand-roll our own purl parser and be done with it. |
Just double checked, and we are not using any configurations besides the default settings. Here's the build process, which is the same as the documentation example: dependency-review:
name: Dependency Review
runs-on: ubuntu-latest
steps:
- name: 'Checkout Repository'
uses: actions/checkout@v4
- name: 'Dependency Review'
uses: actions/dependency-review-action@v4 |
@watercable76 thanks again for the report, this should be fixed now. |
My project is referencing the v4 of dependency review action, and as of the most recent release, there is an error where it won't run anymore due to a 'Error: Invalid purl: version must be percent-encoded'. Nothing else has changed in my code, but the most recent changes to the dependency review action
Looking through the commit history, this was the most recent change, and it was included in the release today -> https://github.com/actions/dependency-review-action/blob/main/src/utils.ts#L73
Is there some way to get this reverted temporarily @juxtin, especially on a Friday afternoon?
The text was updated successfully, but these errors were encountered: