Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add GitHub's dependency-review-action as a linter #16

Merged
merged 1 commit into from
Sep 22, 2022

Conversation

reedloden
Copy link
Contributor

Dependency Review Action

This Action will scan dependency manifest files that change as part of a Pull Request, surfacing known-vulnerable versions of the packages declared or updated in the PR. Once installed, if the workflow run is marked as required, PRs introducing known-vulnerable packages will be blocked from merging.

Source repository: https://github.com/actions/dependency-review-action
Public documentation: https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review#dependency-review-enforcement

Copy link
Contributor

@wadells wadells left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks!

@reedloden reedloden force-pushed the reed/dependency-review branch from 3c09d91 to 31bb999 Compare September 9, 2022 19:47
@reedloden reedloden self-assigned this Sep 22, 2022
Dependency Review Action

This Action will scan dependency manifest files that change as part of a Pull
Request, surfacing known-vulnerable versions of the packages declared or
updated in the PR. Once installed, if the workflow run is marked as required,
PRs introducing known-vulnerable packages will be blocked from merging.

Source repository: https://github.com/actions/dependency-review-action
Public documentation: https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review#dependency-review-enforcement
@reedloden reedloden force-pushed the reed/dependency-review branch from 31bb999 to 4e4392c Compare September 22, 2022 18:36
@reedloden reedloden merged commit 1776ec8 into main Sep 22, 2022
@reedloden reedloden deleted the reed/dependency-review branch September 22, 2022 18:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants