Skip to content

Commit 78c02ed

Browse files
authored
Merge pull request #31 from advanced-security/GeekMasher-patch-1
feat(ci): Update docs for dep-review
2 parents c7b8f08 + d1f88a4 commit 78c02ed

File tree

2 files changed

+9
-4
lines changed

2 files changed

+9
-4
lines changed

.github/workflows/dependency-review.yml

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
# 'Dependency Review' Reusable Workflow
22
#
3-
# Note: Override the default configuration by providing a './.github/dependency-review.yml' in your repo.
3+
# Note: If the default configuration isn't present in your repository, we use the centralised
4+
# configurations.
45

56
name: 'Dependency Review'
67

@@ -10,6 +11,7 @@ on:
1011

1112
permissions:
1213
contents: read
14+
# Required for writing a PR Comment
1315
pull-requests: write
1416

1517
jobs:
@@ -19,6 +21,8 @@ jobs:
1921
- name: 'Checkout Repository'
2022
uses: actions/checkout@v4
2123

24+
# [optional] This setup isn't required but if your repository have a configuration,
25+
# we use that versus the centralised config.
2226
- name: 'Check for configuration file'
2327
id: config
2428
env:
@@ -41,5 +45,7 @@ jobs:
4145
- name: 'Dependency Review'
4246
uses: actions/dependency-review-action@v4
4347
with:
48+
# this value can also be hardcoded to a remote repository
49+
# Example: advanced-security/reusable-workflows/.github/dependency-review.yml@main
4450
config-file: ${{ steps.config.outputs.config }}
4551
comment-summary-in-pr: "always"

.github/workflows/language-detection-and-assignment.yml

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5,8 +5,7 @@ on:
55
branches: [main]
66

77
env:
8-
GH_TOKEN: ${{ github.token }}
9-
8+
GH_TOKEN: ${{ secrets.GH_AP_TOKEN }}
109
jobs:
1110
detect-and-assign:
1211
runs-on: ubuntu-latest
@@ -46,4 +45,4 @@ jobs:
4645
- name: Assign default
4746
if: steps.detect-languages.outputs.java != 'true' && steps.detect-languages.outputs.kotlin != 'true' && steps.detect-languages.outputs.javascript != 'true' && steps.detect-languages.outputs.typescript != 'true' && steps.detect-languages.outputs.go != 'true' && steps.detect-languages.outputs.codeql != 'true' && steps.detect-languages.outputs.python != 'true'
4847
run: |
49-
gh pr edit ${{ github.event.number }} --add-reviewer oss-maintainers
48+
gh pr edit ${{ github.event.number }} --add-reviewer felickz --add-reviewer Geekmasher --add-reviewer adrienpessu

0 commit comments

Comments
 (0)