Skip to content

Install Dependency Review Action#1201

Merged
aeisenberg merged 2 commits intogithub:mainfrom
mrysav:patch-1
Mar 11, 2022
Merged

Install Dependency Review Action#1201
aeisenberg merged 2 commits intogithub:mainfrom
mrysav:patch-1

Conversation

@mrysav
Copy link
Copy Markdown
Contributor

@mrysav mrysav commented Mar 10, 2022

👋 Hello friends! You have been selected try a new offering from the Dependency Graph team. Thank you advance for your help as we test and iterate towards our GA launch.

What is this?

This PR introduces the Dependency Review Action as a workflow on your repository. This Action will run on every pull request, scan changed dependencies, and alert you if the pull request is introducing vulnerabilities into your project.

You can find more details in our staff-ship announcement!

Installation

In order to install the action and get going, you simply have to merge this PR!

❗ As long as you don't make this workflow a required CI job, you won't be blocked by the workflow at all as we refine and prepare for our GA launch. If you are getting failures on your PRs that are not indicative of vulnerable dependencies being present, please let us know what errors you are receiving and we can help you out.

Questions and Comments

We love feedback!

Feel free to drop any feedback you have on our feedback issue. No concern or excitement is too little or too large! 😄

See the README for any other setup questions you have.

If you'd like to talk to a live representative, feel free to swing by and chat with us in the #dependency-graph channel on Slack.

@mrysav mrysav requested a review from a team as a code owner March 10, 2022 19:49
Comment thread .github/workflows/dependency-review.yml
Comment thread .github/workflows/dependency-review.yml Outdated
Copy link
Copy Markdown
Contributor

@aeisenberg aeisenberg left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seems good for now. We can expand the permissions later if necessary.

@aeisenberg aeisenberg enabled auto-merge March 11, 2022 18:30
@aeisenberg aeisenberg merged commit 50d495b into github:main Mar 11, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants