mirror of
https://github.com/goauthentik/authentik.git
synced 2026-06-17 19:09:11 +03:00
91b8f85788
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...df4cb1c069e1874edd31b4311f1884172cec0e10) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 6.0.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
33 lines
1.1 KiB
YAML
33 lines
1.1 KiB
YAML
---
|
|
name: QA - Dependency review
|
|
|
|
# Blocks PRs that introduce a dependency with a known vulnerability above
|
|
# the configured severity threshold. Covers every ecosystem GitHub's
|
|
# Advisory Database supports — for this repo that's npm, Go modules,
|
|
# Python (pip/uv), Cargo, and GitHub Actions.
|
|
|
|
on:
|
|
pull_request:
|
|
branches: [main]
|
|
|
|
permissions:
|
|
contents: read
|
|
pull-requests: write
|
|
|
|
jobs:
|
|
dependency-review:
|
|
name: dependency-review
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 5
|
|
steps:
|
|
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v5
|
|
- uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0
|
|
with:
|
|
# Block PRs that introduce a *new* dependency with a known
|
|
# high/critical vuln. We don't fail on existing vulns — those are
|
|
# surfaced separately via Dependabot.
|
|
fail-on-severity: high
|
|
# Surface a summary comment on the PR itself, in addition to the
|
|
# check status, so reviewers can see the diff at a glance.
|
|
comment-summary-in-pr: on-failure
|