Skip to content

Conversation

@erisu
Copy link
Member

@erisu erisu commented Nov 22, 2025

Request for updating an existing GitHub Action to the allow list

Overview

This GitHub Action is being used to audit the licenses of the project's NPM dependency tree. The purpose of this action is to provide early detection during commits and PR to ensure that updated or newly added npm dependencies follows the ASF 3rd Party Category A License requirements.

Name of action:

erisu/license-checker-action

URL of action:

https://github.com/erisu/license-checker-action

Version to pin to (hash only):

99cffa11264fe545fd0baa6c13bca5a00ae608f2 -> v2.0.1

Permissions

  • None

Related Actions

  • None

Checklist

You should be able to check most of these boxes for an action to be considered for review.
Please check all boxes that currently apply:

  • The action is listed in the GitHub Actions Marketplace
  • The action is not already on the list of approved actions
  • The action has a sufficient number of contributors or has contributors within the ASF community
  • The action has a clearly defined license
  • The action is actively developed or maintained
  • The action has CI/unit tests configured
    • The CI is enabled to run CodeQL against the JS code.
    • Dependabot should also be enabled to monitor the npm dependencies.

@raboof
Copy link
Member

raboof commented Nov 22, 2025

this was picked up by dependabot after all (#384), let's use that regular workflow

@raboof raboof closed this Nov 22, 2025
@erisu erisu deleted the chore/update-erisu-actions branch November 22, 2025 13:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants