mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 07:03:11 +00:00
ci(dependency-review): add optional allow-ghsas pass-through input
Callers with an adjudicated accepted-risk advisory (suppressed with justification in their repo-local .security-review/suppressions.json) had no way to keep the dependency-review check green when a lockfile diff touches a package still inside the vulnerable range. Passes the input straight to actions/dependency-review-action. Default '' is byte-identical to an unset action input, so existing callers are unaffected. First consumer: seahaven-site, allowing GHSA-mh99-v99m-4gvg (brace-expansion, no in-range fix until @11ty/recursive-copy bumps minimatch).
This commit is contained in:
parent
f71002a9ed
commit
80786a4a93
1 changed files with 10 additions and 0 deletions
|
|
@ -1,6 +1,15 @@
|
||||||
name: Dependency Review
|
name: Dependency Review
|
||||||
on:
|
on:
|
||||||
workflow_call:
|
workflow_call:
|
||||||
|
inputs:
|
||||||
|
allow-ghsas:
|
||||||
|
description: >-
|
||||||
|
Comma-separated GHSA IDs to exclude from failing the review.
|
||||||
|
Only for advisories already adjudicated as accepted risk in the
|
||||||
|
calling repo (documented in its .security-review/suppressions.json).
|
||||||
|
type: string
|
||||||
|
required: false
|
||||||
|
default: ''
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
jobs:
|
jobs:
|
||||||
|
|
@ -11,3 +20,4 @@ jobs:
|
||||||
- uses: actions/dependency-review-action@v5
|
- uses: actions/dependency-review-action@v5
|
||||||
with:
|
with:
|
||||||
fail-on-severity: high
|
fail-on-severity: high
|
||||||
|
allow-ghsas: ${{ inputs.allow-ghsas }}
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue