.github/.github/workflows/callable-dependency-review.yaml
Adam Moussa 4a6cbfd362
Some checks failed
ci / ci / ci (push) Has been cancelled
Release on reusable change / version (push) Has been cancelled
Release on reusable change / release (push) Has been cancelled
ci(workflows): pin remaining GitHub Actions to SHA (#139)
Mutable tags and the dependency-review v5 branch executed inside every consumer, including OIDC deploy jobs. SHA pins with version comments match the policy scanner and let Renovate advance them.
2026-08-26 18:25:53 -04:00

23 lines
758 B
YAML

name: Dependency Review
on:
workflow_call:
inputs:
allow-ghsas:
description: >-
Comma-separated GHSA IDs to exclude from failing the review.
Only for advisories already adjudicated as accepted risk in the
calling repo (documented in its .security-review/suppressions.json).
type: string
required: false
default: ''
permissions:
contents: read
jobs:
dependency-review:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0
with:
fail-on-severity: high
allow-ghsas: ${{ inputs.allow-ghsas }}