We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 3bb66d4 commit 8198976Copy full SHA for 8198976
.github/workflows/review-dependencies.yaml
@@ -0,0 +1,24 @@
1
+name: Review dependencies
2
+
3
+on:
4
+ pull_request:
5
+ branches: ['main']
6
+ paths:
7
+ - 'package.json'
8
+ - 'package-lock.json'
9
10
+jobs:
11
+ review:
12
+ runs-on: ubuntu-latest
13
14
+ permissions:
15
+ # Write permissions needed to comment review results on PR.
16
+ # Pwn request risk mitigated by using pull_request workflow trigger
17
+ # and external contributor workflow runs require maintainer approval.
18
+ pull-requests: write
19
20
+ steps:
21
+ - uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
22
+ - uses: actions/dependency-review-action@5a2ce3f5b92ee19cbb1541a4984c76d921601d7c # v4.3.4
23
+ with:
24
+ comment-summary-in-pr: always
0 commit comments