name: Dependency Review
"on":
pull_request:
branches: [main]
permissions:
contents: read
pull-requests: write
jobs:
dependency-review:
name: Dependency Review
runs-on: ubuntu-latest
steps:
- name: Checkout Repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v5
- name: Dependency Review
uses: actions/dependency-review-action@98884d411b0f1c583e5ee579e7e897d4623019c2 # v4
with:
# Fail the build if there are any vulnerabilities
fail-on-severity: low
# Allow licenses (you can restrict this if needed)
allow-licenses: MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC, 0BSD