Skip to content

chore(ci): fail PRs that introduce vulnerable dependencies - #11

Merged
Mtze merged 1 commit into
mainfrom
chore/dependency-review
Aug 27, 2026
Merged

Mtze merged 1 commit into
mainfrom
chore/dependency-review

Conversation

@Mtze

@Mtze Mtze commented Aug 27, 2026

Copy link
Copy Markdown
Member

What and why

Renovate already tells us about vulnerable dependencies sitting on main. Nothing stopped a PR from adding a new one.

This wires up the shared reusable workflow EduIDE/.github/.github/workflows/dependency-review.yml@v1. It runs actions/dependency-review-action over the PR diff and fails the check when the PR introduces a dependency with a known advisory at high severity or above (the reusable workflow's default). It only looks at what the PR adds, so pre-existing findings do not block anyone.

The job goes into the existing CI workflow (.github/workflows/ci.yml), alongside the structure check and the site build, so the PR gates stay in one place.

How it was verified

  • actionlint 1.7.6 run over this repo's workflows. The file changed here is clean. Pre-existing findings in workflows this PR does not touch were left alone.
  • This PR is itself the first run of the check - see the dependency-review entry in the checks list. It adds no dependencies, so it is expected to pass.
  • The underlying API needs the repo to be public (or GitHub Advanced Security on a private repo). This repo is public.

Deployment impact

  • Requires a config or secret change
  • Requires a migration
  • Changes a published artifact or image
  • CI-only change, no runtime impact

Risk and rollback

Low. The change adds a read-only PR check and touches nothing that ships. The one way it can bite: a PR that legitimately needs a dependency carrying a high-severity advisory gets blocked until the dependency is upgraded or swapped.

Rollback: revert this commit. To soften it instead, pass a higher fail-on-severity to the reusable workflow.

Adds the shared EduIDE/.github dependency-review reusable workflow as a job in
the existing CI workflow. It fails a PR that introduces a dependency with a
known advisory at high severity or above, and stays quiet about anything
already on main.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9
@coderabbitai

coderabbitai Bot commented Aug 27, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 28 minutes.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: d11c762b-b8ab-4710-a6ba-c195a130465e

📥 Commits

Reviewing files that changed from the base of the PR and between d57aeee and 8964512.

📒 Files selected for processing (1)
  • .github/workflows/ci.yml

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Mtze
Mtze merged commit 087f652 into main Aug 27, 2026
8 checks passed
@Mtze
Mtze deleted the chore/dependency-review branch August 27, 2026 15:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant