ci(dependency-review): add optional allow-ghsas pass-through input

Callers with an adjudicated accepted-risk advisory (suppressed with
justification in their repo-local .security-review/suppressions.json)
had no way to keep the dependency-review check green when a lockfile
diff touches a package still inside the vulnerable range. Passes the
input straight to actions/dependency-review-action. Default '' is
byte-identical to an unset action input, so existing callers are
unaffected.

First consumer: seahaven-site, allowing GHSA-mh99-v99m-4gvg
(brace-expansion, no in-range fix until @11ty/recursive-copy bumps
minimatch).
This commit is contained in:
Adam Moussa 2026-07-27 13:23:41 -04:00
parent f71002a9ed
commit 80786a4a93
No known key found for this signature in database

View file

@ -1,6 +1,15 @@
name: Dependency Review
on:
workflow_call:
inputs:
allow-ghsas:
description: >-
Comma-separated GHSA IDs to exclude from failing the review.
Only for advisories already adjudicated as accepted risk in the
calling repo (documented in its .security-review/suppressions.json).
type: string
required: false
default: ''
permissions:
contents: read
jobs:
@ -11,3 +20,4 @@ jobs:
- uses: actions/dependency-review-action@v5
with:
fail-on-severity: high
allow-ghsas: ${{ inputs.allow-ghsas }}