Skip to content

feat(ci): Integrate CodeQL, Dependabot, Scorecard, and Dependency Reviews #12

feat(ci): Integrate CodeQL, Dependabot, Scorecard, and Dependency Reviews

feat(ci): Integrate CodeQL, Dependabot, Scorecard, and Dependency Reviews #12

name: 'Dependency Review'
on: [pull_request]
# Declare default permissions as read only.
permissions: read-all
jobs:
dependency-review:
runs-on: ubuntu-latest
permissions:
pull-requests: write
steps:
- name: 'Checkout Repository'
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- name: 'Dependency Review'
uses: actions/dependency-review-action@72eb03d02c7872a771aacd928f3123ac62ad6d3a # v4.3.3
with:
fail-on-severity: high
comment-summary-in-pr: true