Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci: add dependency review job to PR workflow #4631

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

erikgb
Copy link
Contributor

@erikgb erikgb commented Jan 26, 2025

Closes

What changed?

New job in PR workflow including https://github.com/actions/dependency-review-action.

Why was this change made?

Will allow detection of vulnerable dependencies, and could potentially be used to check licenses. Inspired by a StepSecurity analyze of our repo.

How was this change implemented?

How did you validate the change?

Release notes

Documentation Changes

@erikgb erikgb requested a review from casibbald January 26, 2025 15:50
@erikgb erikgb force-pushed the dependency-review branch from 1cfcbf7 to 51355e0 Compare January 26, 2025 15:52
@erikgb erikgb changed the title Dependency review ci: add dependency review job to PR workflow Jan 26, 2025
@erikgb erikgb enabled auto-merge (rebase) January 26, 2025 15:52
@erikgb erikgb force-pushed the dependency-review branch from 51355e0 to a3b7c3c Compare January 26, 2025 15:57
@erikgb erikgb force-pushed the dependency-review branch from a3b7c3c to cf3cbf1 Compare January 26, 2025 16:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant