shoc-backend/.github/workflows/dependency-review.yml
Adam Moussa 38588ac33e
chore(ci): run dependency review as one job on pull requests and merge groups
The merge_group pass-through added in #159 produced a second, skipped check
run with the same name on every pull request, because GitHub reports a check
for a job whose if: is false. The pinned dependency-review action resolves its
refs from merge_group.base_sha and head_sha itself, so the single real job now
triggers on both events with no conditions. Pull requests and merge groups
each get one check run, and the required check is still satisfied in the
queue.
2026-09-18 19:17:02 -04:00

12 lines
465 B
YAML

name: Dependency Review
on:
pull_request:
# The dependency-review action resolves the diff from merge_group.base_sha and
# head_sha itself, so the same job satisfies the required check in the merge
# queue. One job, no conditions, one check run per event.
merge_group:
permissions:
contents: read
jobs:
review:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@4a6cbfd362140a68810f0f46d338026863b8e827 # v1.0.10