From e62de1ca2298299a90d211a9ba365b0ef3229ef1 Mon Sep 17 00:00:00 2001 From: Mitchell Rysavy Date: Thu, 10 Mar 2022 14:48:06 -0500 Subject: [PATCH 1/2] Create dependency-review.yml --- .github/workflows/dependency-review.yml | 11 +++++++++++ 1 file changed, 11 insertions(+) create mode 100644 .github/workflows/dependency-review.yml diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml new file mode 100644 index 000000000..bcb9ba787 --- /dev/null +++ b/.github/workflows/dependency-review.yml @@ -0,0 +1,11 @@ +name: 'Dependency Review' +on: [pull_request] + +jobs: + dependency-review: + runs-on: ubuntu-latest + steps: + - name: 'Checkout Repository' + uses: actions/checkout@v3 + - name: 'Dependency Review' + uses: dsp-testing/dependency-review-action@main From 526d5c2c44d19201bf8e8ab0b7575fa1f2757e5e Mon Sep 17 00:00:00 2001 From: Andrew Eisenberg Date: Fri, 11 Mar 2022 10:29:02 -0800 Subject: [PATCH 2/2] Apply suggestions from code review --- .github/workflows/dependency-review.yml | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index bcb9ba787..c9dff0987 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -1,5 +1,11 @@ name: 'Dependency Review' -on: [pull_request] +on: + - pull_request + - workflow_dispatch + +permissions: + actions: read + pull-requests: read jobs: dependency-review: