chore(ci): add dependency review to PR CI - #39
Merged
Merged
Conversation
Renovate reports advisories on dependencies we already have. This adds the org-wide dependency-review check, which looks only at what a PR introduces and fails on a newly added advisory of high severity or above. It gets its own workflow file: the existing PR-triggered workflows are path filtered to src/ and chart/, and this should run on every PR. The Go module lives in src/ rather than the repo root. GitHub's dependency graph already indexes it, and the action reads the graph rather than the checkout, so no extra configuration is needed. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9
|
Warning Review limit reachedNext included review available in 29 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
Adds the org-wide
dependency-reviewcheck to this repo's PR CI, in a new.github/workflows/dependency-review.yml.Renovate already tells us about advisories on dependencies we have. This covers the other direction: it diffs a PR's dependencies against
mainand fails the PR if it introduces a dependency with a known advisory at high severity or above. Pre-existing advisories are out of scope for this check.It gets its own file rather than a job in an existing workflow because both PR-triggered workflows here are path filtered -
docker-build.ymltosrc/**andchart/**,chart-preview.ymltochart/**- and this should run on every PR.The Go module lives in
src/, not the repo root. That is not a problem: the action reads GitHub's dependency graph rather than the checkout, and the graph already indexessrc/go.mod.How it was verified
actionlintv1.7.6 on the repo: no findings in the new file. The SC2086 infos it reports are pre-existing, inchart-preview.yml,docker-build.ymlandrelease.yml, and untouched here.src/layout concern directly against the API (GET /repos/EduIDE/EduIDE-shared-cache/dependency-graph/sbom): 65 Go packages are indexed, so the non-root module is picked up and the action has something to compare.Deployment impact
versionbumped)CI only. The chart and the image are untouched, so no chart version bump.
Risk and rollback
Low. Worst case is a false positive blocking a PR, which is not silent - the job log names the offending package and advisory. It is not a required check unless someone makes it one, so it can be overridden by merging anyway.
Rollback: revert this commit, or delete
.github/workflows/dependency-review.yml.