Sourced from actions/dependency-review-action's releases.
v4.7.0
- Handle complex license expressions (e.g.
MIT AND GPL-2.0
) in allow lists (fixes #809 and probably others)- Replace
OTHER
in package licenses withLicenseRef-clearlydefined-OTHER
so that parsing passes
38ecb5b
Merge pull request #929
from actions/dangoor/4.7-release0e9e935
Version 4.7.0 release69d2faa
Merge pull request #926
from dangoor/dangoor/replace-other7e14978
Merge branch 'actions:main' into dangoor/replace-other8477905
Merge pull request #927
from dangoor/dangoor/multilicensef3ff356
Update distc7565d4
Fix tests and respond to review feedback82299c3
Replace OTHER with a LicenseRef2013ccc
Update type definition for spdx-satisfies3a2b687
Handle complex licenses (e.g. X AND Y)