From 07ce007bad08fdcf07409a5f372baabda8781354 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 27 Jul 2026 13:35:47 -0400 Subject: [PATCH] ci(dependency-review): add optional allow-ghsas pass-through input (#89) Callers with an adjudicated accepted-risk advisory (suppressed with justification in their repo-local .security-review/suppressions.json) had no way to keep the dependency-review check green when a lockfile diff touches a package still inside the vulnerable range. Passes the input straight to actions/dependency-review-action. Default '' is byte-identical to an unset action input, so existing callers are unaffected. First consumer: seahaven-site, allowing GHSA-mh99-v99m-4gvg (brace-expansion, no in-range fix until @11ty/recursive-copy bumps minimatch). --- .github/workflows/callable-dependency-review.yaml | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/.github/workflows/callable-dependency-review.yaml b/.github/workflows/callable-dependency-review.yaml index e186044..434fd71 100644 --- a/.github/workflows/callable-dependency-review.yaml +++ b/.github/workflows/callable-dependency-review.yaml @@ -1,6 +1,15 @@ name: Dependency Review on: workflow_call: + inputs: + allow-ghsas: + description: >- + Comma-separated GHSA IDs to exclude from failing the review. + Only for advisories already adjudicated as accepted risk in the + calling repo (documented in its .security-review/suppressions.json). + type: string + required: false + default: '' permissions: contents: read jobs: @@ -11,3 +20,4 @@ jobs: - uses: actions/dependency-review-action@v5 with: fail-on-severity: high + allow-ghsas: ${{ inputs.allow-ghsas }}