Remove the dependency-review action #3641
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What type of PR is this?
/kind cleanup
What this PR does / why we need it:
This PR removes the dependency-review GitHub Action because it doesn't work well with some packages such as
golang.org/x/oauth2
. This is often blocking merges to this repository so we have to manually merge PRs. This has been reported to the upstream a few months ago but we didn't receive any feedback as of now: actions/dependency-review-action#736For the time being, let's remove this action and consider if we can replace it with something else. I'll create a follow up issue for that.
Which issue(s) this PR fixes:
xref actions/dependency-review-action#736
xref https://kubernetes.slack.com/archives/CJH2GBF7Y/p1718018117653269
Does this PR introduce a user-facing change?
/assign @saschagrunert @cpanato @Verolop @puerco
cc @kubernetes/release-engineering