shoc-backend/.github/workflows/dependency-review.yml
Adam Moussa 1888b66940
Some checks are pending
Architecture and changed-file quality / architecture (push) Waiting to run
Backend CI / Build and test (push) Waiting to run
ci: run required checks on merge_group for the merge queue (#159)
Build and test, architecture, and dependency-review are the required checks
on main. A merge queue only counts checks that ran on the merge_group event,
so each workflow now triggers on it. The architecture gate reads the merge
group's own base and head because github.event.before is empty there. The
dependency-review action cannot diff a merge group, so that event reports the
same check name from a pass-through job; the real review already gated the
pull request before it could be queued.
2026-09-18 18:16:10 -04:00

21 lines
831 B
YAML

name: Dependency Review
on:
pull_request:
merge_group:
permissions:
contents: read
jobs:
review:
if: github.event_name == 'pull_request'
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@4a6cbfd362140a68810f0f46d338026863b8e827 # v1.0.10
# The dependency-review action only diffs a pull request, and the org callable
# does not take explicit base and head refs. Every pull request in a merge
# group already passed the real review above before it could be queued, so the
# merge group reports the same required check name and passes.
review-merge-group:
if: github.event_name == 'merge_group'
name: review / dependency-review
runs-on: ubuntu-latest
steps:
- run: echo "Dependency review ran on the pull request before it entered the merge queue."