From b6494899b158361e5debec2f4c1d5579b9bbc346 Mon Sep 17 00:00:00 2001 From: naveensrinivasan <172697+naveensrinivasan@users.noreply.github.com> Date: Fri, 9 Feb 2024 11:58:20 -0600 Subject: [PATCH 1/3] Included dependency review action - Included dependency review action https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review#dependency-review-enforcement Signed-off-by: naveensrinivasan <172697+naveensrinivasan@users.noreply.github.com> --- .github/workflows/dependency-review.yml | 14 ++++++++++++++ 1 file changed, 14 insertions(+) create mode 100644 .github/workflows/dependency-review.yml diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml new file mode 100644 index 0000000000..107edba26a --- /dev/null +++ b/.github/workflows/dependency-review.yml @@ -0,0 +1,14 @@ +name: 'Dependency Review' +on: [pull_request] + +permissions: + contents: read + +jobs: + validate: + runs-on: ubuntu-latest + steps: + - name: 'Checkout Repository' + uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3.6.0 + - name: 'Dependency Review' + uses: actions/dependency-review-action@0efb1d1d84fc9633afcdaad14c485cbbc90ef46c # v2.5.1 From ccf6732f689325faab0e222516f52da1eca935a3 Mon Sep 17 00:00:00 2001 From: Wayne Starr Date: Fri, 16 Feb 2024 16:24:38 -0700 Subject: [PATCH 2/3] Update .github/workflows/dependency-review.yml Co-authored-by: razzle --- .github/workflows/dependency-review.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 107edba26a..6342988b07 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -1,5 +1,5 @@ -name: 'Dependency Review' -on: [pull_request] +name: Dependency Review +on: pull_request permissions: contents: read From 07d1ca592fd2d9bfeba4cf46b250154ee530fd7f Mon Sep 17 00:00:00 2001 From: Wayne Starr Date: Fri, 16 Feb 2024 16:24:42 -0700 Subject: [PATCH 3/3] Update .github/workflows/dependency-review.yml Co-authored-by: razzle --- .github/workflows/dependency-review.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 6342988b07..03833afb78 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -8,7 +8,7 @@ jobs: validate: runs-on: ubuntu-latest steps: - - name: 'Checkout Repository' + - name: Checkout uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3.6.0 - - name: 'Dependency Review' + - name: Dependency Review uses: actions/dependency-review-action@0efb1d1d84fc9633afcdaad14c485cbbc90ef46c # v2.5.1