Skip to content

Commit 8db3d9f

Browse files
authored
Merge pull request #404 from Automattic/add/dep-review
ci: add Dependency Review workflow
2 parents 1e9092c + c27f8f7 commit 8db3d9f

File tree

1 file changed

+24
-0
lines changed

1 file changed

+24
-0
lines changed
Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
name: Dependency Review
2+
3+
on:
4+
pull_request:
5+
6+
permissions:
7+
contents: read
8+
9+
jobs:
10+
dependency-review:
11+
runs-on: ubuntu-latest
12+
name: Review Dependencies
13+
permissions:
14+
contents: read
15+
pull-requests: write
16+
steps:
17+
- name: Check out the source code
18+
uses: actions/[email protected]
19+
20+
- name: Review dependencies
21+
uses: actions/[email protected]
22+
with:
23+
comment-summary-in-pr: true
24+
show-openssf-scorecard: true

0 commit comments

Comments
 (0)