.github/.github/workflows/callable-dependency-review.yaml
Adam Moussa fc75158c94
docs: refresh .github README and workflow-templates (INFRA-142) (#73)
- README: mark compliance-audit.yaml deprecated (2026-06-10), document all
  12 reusable workflows (was 6), add workflow-templates and action-pinning
  policy sections
- dependency-review.yml template: convert to thin caller of
  callable-dependency-review.yaml (was inlining dependency-review-action@v4,
  drifted from callable @v5)
- callable-dependency-review.yaml: preserve comment-summary-in-pr on-failure
  and grant pull-requests: write
- add labeler.yml + labeler.properties.json starter template
2026-07-08 16:21:37 -04:00

15 lines
338 B
YAML

name: Dependency Review
on:
workflow_call:
permissions:
contents: read
pull-requests: write
jobs:
dependency-review:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/dependency-review-action@v5
with:
fail-on-severity: high
comment-summary-in-pr: on-failure