diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 9b9e6fd..8daba8b 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -1,21 +1,12 @@ name: Dependency Review on: pull_request: + # The dependency-review action resolves the diff from merge_group.base_sha and + # head_sha itself, so the same job satisfies the required check in the merge + # queue. One job, no conditions, one check run per event. merge_group: permissions: contents: read jobs: review: - if: github.event_name == 'pull_request' uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@4a6cbfd362140a68810f0f46d338026863b8e827 # v1.0.10 - - # The dependency-review action only diffs a pull request, and the org callable - # does not take explicit base and head refs. Every pull request in a merge - # group already passed the real review above before it could be queued, so the - # merge group reports the same required check name and passes. - review-merge-group: - if: github.event_name == 'merge_group' - name: review / dependency-review - runs-on: ubuntu-latest - steps: - - run: echo "Dependency review ran on the pull request before it entered the merge queue."