Citi / scaler

Efficient, lightweight and reliable distributed computation engine
Apache License 2.0
12 stars 4 forks source link

Enable DependencyReview GitHub Action 🔍 📦 #4

Closed JamieSlome closed 2 months ago

JamieSlome commented 3 months ago

The dependency review action scans your pull requests for dependency changes, and will raise an error if any vulnerabilities or invalid licenses are being introduced. The action is supported by an API endpoint that diffs the dependencies between any two revisions on your default branch.

name: 'Dependency Review'
on: [pull_request]

permissions:
  contents: read

jobs:
  dependency-review:
    runs-on: ubuntu-latest
    steps:
      - name: 'Checkout Repository'
        uses: actions/checkout@v4
      - name: 'Dependency Review'
        uses: actions/dependency-review-action@v4
JamieSlome commented 2 months ago

Addressed in #5