We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 32f34bb commit a06b161Copy full SHA for a06b161
.github/workflows/dependency-review.yml
@@ -9,12 +9,14 @@
9
name: 'Dependency Review'
10
on: [pull_request]
11
12
-permissions:
13
- contents: read
+permissions: {}
14
15
jobs:
16
dependency-review:
17
runs-on: ubuntu-latest
+ permissions:
18
+ contents: read
19
+ pull-requests: write
20
steps:
21
- name: Harden the runner (Audit all outbound calls)
22
uses: step-security/harden-runner@6c439dc8bdf85cadbbce9ed30d1c7b959517bc49 # v2.12.2
@@ -27,3 +29,5 @@ jobs:
27
29
persist-credentials: false
28
30
- name: 'Dependency Review'
31
uses: actions/dependency-review-action@da24556b548a50705dd671f47852072ea4c105d9 # v4.7.1
32
+ with:
33
+ comment-summary-in-pr: always
0 commit comments