From 6306cbc266a64a17a3e03157d728ad7d49c94108 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?S=C3=A9bastien=20Lorber?= Date: Wed, 13 Apr 2022 19:22:00 +0200 Subject: [PATCH] misc: add CI actions/dependency-review-action for security (#7168) --- .github/workflows/canary-release.yml | 2 +- .github/workflows/dependency-review.yml | 14 ++++++++++++++ 2 files changed, 15 insertions(+), 1 deletion(-) create mode 100644 .github/workflows/dependency-review.yml diff --git a/.github/workflows/canary-release.yml b/.github/workflows/canary-release.yml index 7b9f217dad..9b6b8829ea 100644 --- a/.github/workflows/canary-release.yml +++ b/.github/workflows/canary-release.yml @@ -15,7 +15,7 @@ jobs: name: Publish Canary runs-on: ubuntu-latest steps: - - uses: actions/checkout@a12a3943b4bdde767164f792f33f40b04645d846 #v3 + - uses: actions/checkout@a12a3943b4bdde767164f792f33f40b04645d846 # v3 with: fetch-depth: 0 # Needed to get the commit number with "git rev-list --count HEAD" - name: Set up Node diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml new file mode 100644 index 0000000000..2ef3f97b1d --- /dev/null +++ b/.github/workflows/dependency-review.yml @@ -0,0 +1,14 @@ +name: 'Dependency Review' +on: [pull_request] + +permissions: + contents: read + +jobs: + dependency-review: + runs-on: ubuntu-latest + steps: + - name: 'Checkout Repository' + - uses: actions/checkout@a12a3943b4bdde767164f792f33f40b04645d846 #v3 + - name: 'Dependency Review' + uses: actions/dependency-review-action@3f943b86c9a289f4e632c632695e2e0898d9d67d # v1