Skip to content

Conversation

@Aleksander-Karlsson
Copy link

@Aleksander-Karlsson Aleksander-Karlsson commented Jan 28, 2026

Why:

To keep documentation up to date with Dependency review action.

According to Dependency review action docs this is already deprecated, and might be removed.

⚠️ This option is deprecated for possible removal in the next major release. See Deprecate the deny-licenses option #938 for more information.
Contains a list of prohibited licenses. The action will fail on pull requests that introduce dependencies with licenses that match the list.

ref section https://github.com/actions/dependency-review-action/blob/main/README.md#configuration

Closes:

What's being changed (if available, include any code snippets, screenshots, or gifs):

Removed the bullet point suggesting that using deny-list instead of allow-list for licenses is best practice.

Check off the following:

  • A subject matter expert (SME) has reviewed the technical accuracy of the content in this PR. In most cases, the author can be the SME. Open source contributions may require an SME review from GitHub staff.
  • The changes in this PR meet the docs fundamentals that are required for all content.
  • All CI checks are passing and the changes look good in the review environment.

According to Dependency review action docs this is already deprecated, and might be removed

> ⚠️ This option is deprecated for possible removal in the next major release. See [Deprecate the deny-licenses option github#938](actions/dependency-review-action#938) for more information. <br> Contains a list of prohibited licenses. The action will fail on pull requests that introduce dependencies with licenses that match the list.

ref section https://github.com/actions/dependency-review-action/blob/main/README.md#configuration
@github-actions github-actions bot added the triage Do not begin working on this issue until triaged by the team label Jan 28, 2026
@github-actions
Copy link
Contributor

github-actions bot commented Jan 28, 2026

How to review these changes 👓

Thank you for your contribution. To review these changes, choose one of the following options:

A Hubber will need to deploy your changes internally to review.

Table of review links

Note: Please update the URL for your staging server or codespace.

The table shows the files in the content directory that were changed in this pull request. This helps you review your changes on a staging server. Changes to the data directory are not included in this table.

Source Review Production What Changed
code-security/how-tos/secure-your-supply-chain/manage-your-dependency-security/configuring-the-dependency-review-action.md fpt
ghec
ghes@ 3.19 3.18 3.17 3.16 3.15 3.14
fpt
ghec
ghes@ 3.19 3.18 3.17 3.16 3.15 3.14
code-security/tutorials/secure-your-dependencies/customizing-your-dependency-review-action-configuration.md fpt
ghec
ghes@ 3.19 3.18 3.17 3.16 3.15 3.14
fpt
ghec
ghes@ 3.19 3.18 3.17 3.16 3.15 3.14

Key: fpt: Free, Pro, Team; ghec: GitHub Enterprise Cloud; ghes: GitHub Enterprise Server

🤖 This comment is automatically generated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

triage Do not begin working on this issue until triaged by the team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant