Skip to content

Commit b94681b

Browse files
authored
[meta] add dependency-review workflow
1 parent 9be54c5 commit b94681b

File tree

1 file changed

+30
-0
lines changed

1 file changed

+30
-0
lines changed
Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
1+
name: 'Dependency Review'
2+
on: [pull_request]
3+
permissions:
4+
contents: read
5+
jobs:
6+
dependency-review:
7+
runs-on: ubuntu-latest
8+
steps:
9+
- name: 'Checkout Repository'
10+
uses: actions/checkout@v3
11+
- name: 'Dependency Review'
12+
uses: actions/dependency-review-action@v2
13+
with:
14+
# Possible values: "critical", "high", "moderate", "low"
15+
# fail-on-severity: critical
16+
#
17+
# Possible values in comma separated list: "unknown", "runtime", or "development"
18+
fail-on-scopes: unknown, runtime, development
19+
#
20+
# Possible values: Any available git ref
21+
# base-ref: ${{ github.event.pull_request.base.ref }}
22+
# head-ref: ${{ github.event.pull_request.head.ref }}
23+
#
24+
# You can only include one of these two options: `allow-licenses` and `deny-licenses`. These options are not supported on Enterprise Server.
25+
#
26+
# Possible values: Any `spdx_id` value(s) from https://docs.github.com/en/rest/licenses
27+
# allow-licenses: GPL-3.0, BSD-3-Clause, MIT
28+
#
29+
# Possible values: Any `spdx_id` value(s) from https://docs.github.com/en/rest/licenses
30+
# deny-licenses: LGPL-2.0, BSD-2-Clause

0 commit comments

Comments
 (0)