We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 5561e0a commit 6fe5a5dCopy full SHA for 6fe5a5d
.github/workflows/dependency-review.yml
@@ -0,0 +1,22 @@
1
+name: 'Dependency Review'
2
+on: [pull_request]
3
+
4
+permissions:
5
+ contents: read
6
+ pull-requests: write
7
8
+jobs:
9
+ dependency-review:
10
+ runs-on: ubuntu-latest
11
+ steps:
12
+ - name: 'Checkout Repository'
13
+ uses: actions/checkout@v4
14
15
+ - name: 'Dependency Review'
16
+ uses: actions/dependency-review-action@v4
17
+ with:
18
+ fail-on-severity: high
19
+ fail-on-scopes: runtime, unknown, development
20
+ comment-summary-in-pr: on-failure
21
+ show-openssf-scorecard: true
22
+ retry-on-snapshot-warnings: true
0 commit comments