seahaven-site/.github/workflows/dependency-review.yml
Adam Moussa 3a8de4e88b
feat(ci): deploy the marketing site through the org static caller (PLAT-225) (#69)
* feat(ci): deploy the marketing site through the org static caller (PLAT-225)

Prod still ships on merge to main. Exec roles leave this workspace, and the deploy reads the bucket and distribution from SSM.

* fix(ci): run the static check after the legacy ci job

Both jobs call ci-static, which cancels the other in-progress run on the same ref, so ci-complete never saw both succeed.

* fix(ci): address review feedback

* fix(ci): address review feedback

* fix(ci): address review feedback

* fix(ci): address review feedback
2026-09-25 15:18:40 +00:00

15 lines
538 B
YAML

name: Dependency Review
on:
pull_request:
permissions:
contents: read
jobs:
review:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@0a1010e63248c9ca9f042c870eb2c579ba6b9455 # v1.0.19
with:
# brace-expansion OOM DoS: no in-range fix (patch only in 5.0.8; @11ty/recursive-copy
# pins minimatch <10.0.3). Build-time-only exposure, adjudicated in
# .security-review/suppressions.json — remove when recursive-copy bumps minimatch.
allow-ghsas: GHSA-mh99-v99m-4gvg