Skip to content

Commit f24a714

Browse files
committed
Dont make CI fail on vulnerabilities
1 parent 6f9f33e commit f24a714

File tree

1 file changed

+8
-1
lines changed

1 file changed

+8
-1
lines changed

.github/workflows/ci.yml

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,8 @@ concurrency:
1111

1212
permissions:
1313
contents: read
14-
14+
pull-requests: write
15+
1516
jobs:
1617
find-changed-workspaces:
1718
name: Detect workspace changes
@@ -168,6 +169,8 @@ jobs:
168169
169170
dependency-review:
170171
runs-on: ubuntu-latest
172+
permissions:
173+
pull-requests: write
171174
steps:
172175
- name: Harden Runner
173176
uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
@@ -176,5 +179,9 @@ jobs:
176179

177180
- name: "Checkout Repository"
178181
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
182+
179183
- name: "Dependency Review"
180184
uses: actions/dependency-review-action@595b5aeba73380359d98a5e087f648dbb0edce1b # v4.7.3
185+
with:
186+
warn-only: true
187+
comment-summary-in-pr: on-failure

0 commit comments

Comments
 (0)