bridgy-fed/workflows/dependency-review.yaml

18 wiersze
551 B
YAML

# Prevents merging dependency versions w/vulnerabilities
# https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review
# https://github.com/actions/dependency-review-action#installation=
name: 'Dependency Review'
on: [pull_request]
permissions:
contents: read
jobs:
dependency-review:
runs-on: ubuntu-latest
steps:
- name: 'Checkout Repository'
uses: actions/checkout@v3
- name: 'Dependency Review'
uses: actions/dependency-review-action@v1