Skip to content

update: refer to JSON config file from target branch #18

update: refer to JSON config file from target branch

update: refer to JSON config file from target branch #18

name: Dependency Review
on:
push:
branches: [main]
pull_request:
types: [opened, synchronize]
permissions:
contents: read
pull-requests: write
jobs:
dependency-review:
runs-on: ubuntu-latest
if: github.event_name == 'pull_request'
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- name: Dependency Review
uses: actions/dependency-review-action@da24556b548a50705dd671f47852072ea4c105d9 # v4
with:
fail-on-severity: high
comment-summary-in-pr: on-failure