name: Dependency Review on: pull_request: merge_group: permissions: contents: read jobs: review: if: github.event_name == 'pull_request' uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@4a6cbfd362140a68810f0f46d338026863b8e827 # v1.0.10 # The dependency-review action only diffs a pull request, and the org callable # does not take explicit base and head refs. Every pull request in a merge # group already passed the real review above before it could be queued, so the # merge group reports the same required check name and passes. review-merge-group: if: github.event_name == 'merge_group' name: review / dependency-review runs-on: ubuntu-latest steps: - run: echo "Dependency review ran on the pull request before it entered the merge queue."