From 16e8a17e3a3ab6dfce372155d7c40a2089f62415 Mon Sep 17 00:00:00 2001 From: Aleksander Zaruczewski Date: Thu, 28 Jul 2022 17:09:46 +0300 Subject: [PATCH] add Dependency Review GitHub Actions workflow (#23) --- .github/workflows/dependency_review.yml | 13 +++++++++++++ CHANGELOG.md | 3 ++- 2 files changed, 15 insertions(+), 1 deletion(-) create mode 100644 .github/workflows/dependency_review.yml diff --git a/.github/workflows/dependency_review.yml b/.github/workflows/dependency_review.yml new file mode 100644 index 0000000..c6a7a08 --- /dev/null +++ b/.github/workflows/dependency_review.yml @@ -0,0 +1,13 @@ +name: Dependency Review + +on: + pull_request_target: + branches: + - main + +jobs: + dependency-review: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v3 + - uses: actions/dependency-review-action@v2 diff --git a/CHANGELOG.md b/CHANGELOG.md index 0510d31..818614d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -13,7 +13,8 @@ to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). - `markdownlint` GitHub Actions workflow - `dependabot.yml` GitHub config -- `changelog-enforcer.yml` GitHub Actions workflow +- `changelog_enforcer.yml` GitHub Actions workflow +- `dependency_review.yml` GitHub Actions workflow