mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 05:53:12 +00:00
ci(dependency-review): add optional allow-ghsas pass-through input (#89)
Callers with an adjudicated accepted-risk advisory (suppressed with justification in their repo-local .security-review/suppressions.json) had no way to keep the dependency-review check green when a lockfile diff touches a package still inside the vulnerable range. Passes the input straight to actions/dependency-review-action. Default '' is byte-identical to an unset action input, so existing callers are unaffected. First consumer: seahaven-site, allowing GHSA-mh99-v99m-4gvg (brace-expansion, no in-range fix until @11ty/recursive-copy bumps minimatch).
This commit is contained in:
parent
f71002a9ed
commit
07ce007bad
1 changed files with 10 additions and 0 deletions
|
|
@ -1,6 +1,15 @@
|
|||
name: Dependency Review
|
||||
on:
|
||||
workflow_call:
|
||||
inputs:
|
||||
allow-ghsas:
|
||||
description: >-
|
||||
Comma-separated GHSA IDs to exclude from failing the review.
|
||||
Only for advisories already adjudicated as accepted risk in the
|
||||
calling repo (documented in its .security-review/suppressions.json).
|
||||
type: string
|
||||
required: false
|
||||
default: ''
|
||||
permissions:
|
||||
contents: read
|
||||
jobs:
|
||||
|
|
@ -11,3 +20,4 @@ jobs:
|
|||
- uses: actions/dependency-review-action@v5
|
||||
with:
|
||||
fail-on-severity: high
|
||||
allow-ghsas: ${{ inputs.allow-ghsas }}
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue