Add dependency-review caller workflow #40

Merged
amoussa1229 merged 4 commits from chore/add-dependency-review into main 2026-06-05 16:26:28 +00:00
amoussa1229 commented 2026-06-05 15:42:07 +00:00 (Migrated from github.com)

Summary

Add a pull_request-triggered caller workflow that invokes the org-level callable-dependency-review.yaml@main reusable workflow to scan dependency changes and fail on high-severity advisories.

Validation

Caller references Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@main. Runs on PRs.

Tests

N/A — CI workflow addition; exercised by the Dependency Review check on this PR once the callable workflow is on main.

Notes

Depends on Sea-Haven-Industries/.github#36 (the callable workflow) being merged to main.

## Summary Add a `pull_request`-triggered caller workflow that invokes the org-level `callable-dependency-review.yaml@main` reusable workflow to scan dependency changes and fail on high-severity advisories. ## Validation Caller references `Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@main`. Runs on PRs. ## Tests N/A — CI workflow addition; exercised by the Dependency Review check on this PR once the callable workflow is on main. ## Notes Depends on Sea-Haven-Industries/.github#36 (the callable workflow) being merged to `main`.
github-advanced-security[bot] (Migrated from github.com) reviewed 2026-06-05 15:43:00 +00:00
@ -0,0 +3,4 @@
pull_request:
jobs:
review:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@main
github-advanced-security[bot] (Migrated from github.com) commented 2026-06-05 15:43:00 +00:00

CodeQL / Workflow does not contain permissions

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {{}}

Show more details

## CodeQL / Workflow does not contain permissions Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {{}} [Show more details](https://github.com/Sea-Haven-Industries/seahaven-slack-bot/security/code-scanning/2)
This repo is archived. You cannot comment on pull requests.
No description provided.