apm-wo-analysis/.github/workflows/dependency-review.yml
Adam Moussa 299ead89b3
Some checks are pending
Deploy / deploy (push) Waiting to run
chore: resolve open code scanning alerts (URL host matching + workflow permissions) (#36)
* fix: Refactor `comment_intent` to use `_contains_url_with_host` for URL host matching.

* ci: add least-privilege permissions blocks to workflow callers
Resolves code scanning alerts #4 and #5 (actions/missing-workflow-permissions). Both callable workflows only need contents: read; the dependency-review callable already declares it internally, this caps the caller token to match.
2026-07-23 19:10:45 +00:00

10 lines
229 B
YAML

name: Dependency Review
on:
pull_request:
permissions:
contents: read
jobs:
review:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main