Add dependency-review caller workflow #40
No reviewers
Labels
No labels
app
bug
ci
compliance
dependencies
docker
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/seahaven-slack-bot#40
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "chore/add-dependency-review"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Add a
pull_request-triggered caller workflow that invokes the org-levelcallable-dependency-review.yaml@mainreusable workflow to scan dependency changes and fail on high-severity advisories.Validation
Caller references
Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@main. Runs on PRs.Tests
N/A — CI workflow addition; exercised by the Dependency Review check on this PR once the callable workflow is on main.
Notes
Depends on Sea-Haven-Industries/.github#36 (the callable workflow) being merged to
main.@ -0,0 +3,4 @@pull_request:jobs:review:uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@mainCodeQL / Workflow does not contain permissions
Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {{}}
Show more details