diff --git a/.github/workflows/dependency_review.yml b/.github/workflows/dependency_review.yml new file mode 100644 index 0000000..c6a7a08 --- /dev/null +++ b/.github/workflows/dependency_review.yml @@ -0,0 +1,13 @@ +name: Dependency Review + +on: + pull_request_target: + branches: + - main + +jobs: + dependency-review: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v3 + - uses: actions/dependency-review-action@v2 diff --git a/CHANGELOG.md b/CHANGELOG.md index 0510d31..818614d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -13,7 +13,8 @@ to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). - `markdownlint` GitHub Actions workflow - `dependabot.yml` GitHub config -- `changelog-enforcer.yml` GitHub Actions workflow +- `changelog_enforcer.yml` GitHub Actions workflow +- `dependency_review.yml` GitHub Actions workflow