Skip to content

chore(config dev): actionlint for github and dev container image tag #99

chore(config dev): actionlint for github and dev container image tag

chore(config dev): actionlint for github and dev container image tag #99

name: Dependency Scanning
on:
pull_request:
types: [opened, synchronize, edited]
branches:
- main
workflow_call:
inputs:
severity:
description: Severity to fail on from low, moderate, high, or critical
required: false
type: string
default: low
comment:
description: Comment on PR, from never, always, or on-failure
required: false
type: string
default: on-failure
harden_runner:
description: "Harden the runner"
required: false
default: true
type: boolean
permissions: {}
concurrency:
group: dependency-review-${{ github.repository }}-${{ github.ref }}
cancel-in-progress: true
jobs:
dependency-review:
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: write
steps:
- name: Harden the runner
uses: step-security/harden-runner@17d0e2bd7d51742c71671bd19fa12bdc9d40a3d6 # v2.8.1
if: ${{ inputs.harden_runner != false }}
with:
disable-sudo: true
egress-policy: block
allowed-endpoints: >
api.deps.dev:443
api.github.com:443
api.securityscorecards.dev:443
github.com:443
- name: Checkout Repository
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
- name: Dependency Review
uses: actions/dependency-review-action@72eb03d02c7872a771aacd928f3123ac62ad6d3a # v4.3.3
with:
fail-on-severity: ${{ inputs.severity || 'low' }}
comment-summary-in-pr: ${{ inputs.comment || 'always' }}