Skip to content

ci: add dependency-review-action on PRs#207

Merged
tonyandrewmeyer merged 1 commit into
canonical:mainfrom
tonyandrewmeyer:chore/dependency-review-action
Jun 11, 2026
Merged

ci: add dependency-review-action on PRs#207
tonyandrewmeyer merged 1 commit into
canonical:mainfrom
tonyandrewmeyer:chore/dependency-review-action

Conversation

@tonyandrewmeyer

Copy link
Copy Markdown
Contributor

This PR adds scans of dependency manifest changes introduced in pull requests against the OSV vulnerability database and the configured licence policy, and comments on the PR when a high-severity vulnerability is found so it can be addressed before merge.

It does introduce a new action, but it's an official GitHub one, and the logical companion to dependabot.

Scans dependency manifest changes introduced in pull requests against the
OSV vulnerability database and the configured licence policy, and comments
on the PR when a high-severity vulnerability is found so it can be addressed
before merge.
@tonyandrewmeyer tonyandrewmeyer requested a review from tromai June 10, 2026 03:22
@tonyandrewmeyer tonyandrewmeyer merged commit 4fd2092 into canonical:main Jun 11, 2026
40 checks passed
@tonyandrewmeyer tonyandrewmeyer deleted the chore/dependency-review-action branch June 11, 2026 00:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants