Skip to content

Commit 6fe5a5d

Browse files
committed
Add GitHub Actions workflow for dependency review
1 parent 5561e0a commit 6fe5a5d

File tree

1 file changed

+22
-0
lines changed

1 file changed

+22
-0
lines changed
Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
name: 'Dependency Review'
2+
on: [pull_request]
3+
4+
permissions:
5+
contents: read
6+
pull-requests: write
7+
8+
jobs:
9+
dependency-review:
10+
runs-on: ubuntu-latest
11+
steps:
12+
- name: 'Checkout Repository'
13+
uses: actions/checkout@v4
14+
15+
- name: 'Dependency Review'
16+
uses: actions/dependency-review-action@v4
17+
with:
18+
fail-on-severity: high
19+
fail-on-scopes: runtime, unknown, development
20+
comment-summary-in-pr: on-failure
21+
show-openssf-scorecard: true
22+
retry-on-snapshot-warnings: true

0 commit comments

Comments
 (0)