Skip to content

chore(ci): add dependency review to PR CI - #39

Merged
Mtze merged 1 commit into
mainfrom
chore/dependency-review
Aug 27, 2026
Merged

Mtze merged 1 commit into
mainfrom
chore/dependency-review

Conversation

@Mtze

@Mtze Mtze commented Aug 27, 2026

Copy link
Copy Markdown
Member

What and why

Adds the org-wide dependency-review check to this repo's PR CI, in a new .github/workflows/dependency-review.yml.

Renovate already tells us about advisories on dependencies we have. This covers the other direction: it diffs a PR's dependencies against main and fails the PR if it introduces a dependency with a known advisory at high severity or above. Pre-existing advisories are out of scope for this check.

It gets its own file rather than a job in an existing workflow because both PR-triggered workflows here are path filtered - docker-build.yml to src/** and chart/**, chart-preview.yml to chart/** - and this should run on every PR.

The Go module lives in src/, not the repo root. That is not a problem: the action reads GitHub's dependency graph rather than the checkout, and the graph already indexes src/go.mod.

How it was verified

  • actionlint v1.7.6 on the repo: no findings in the new file. The SC2086 infos it reports are pre-existing, in chart-preview.yml, docker-build.yml and release.yml, and untouched here.
  • Checked the src/ layout concern directly against the API (GET /repos/EduIDE/EduIDE-shared-cache/dependency-graph/sbom): 65 Go packages are indexed, so the non-root module is picked up and the action has something to compare.
  • Confirmed the repo is public. The advisory API behind this action needs GitHub Advanced Security on private repos; this one is public, so it works on the free tier.
  • The check's own run on this PR is the real test. Its result is visible in the checks list below.

Deployment impact

  • Changes a Helm chart (chart version bumped)
  • Changes a published image
  • Requires a config change in EduIDE-deployment
  • Requires a cluster-level change (CRDs, Gateway, ClusterRoles)
  • None of the above

CI only. The chart and the image are untouched, so no chart version bump.

Risk and rollback

Low. Worst case is a false positive blocking a PR, which is not silent - the job log names the offending package and advisory. It is not a required check unless someone makes it one, so it can be overridden by merging anyway.

Rollback: revert this commit, or delete .github/workflows/dependency-review.yml.

Renovate reports advisories on dependencies we already have. This adds the
org-wide dependency-review check, which looks only at what a PR introduces
and fails on a newly added advisory of high severity or above.

It gets its own workflow file: the existing PR-triggered workflows are path
filtered to src/ and chart/, and this should run on every PR.

The Go module lives in src/ rather than the repo root. GitHub's dependency
graph already indexes it, and the action reads the graph rather than the
checkout, so no extra configuration is needed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9
@coderabbitai

coderabbitai Bot commented Aug 27, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 29 minutes.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: ca6914a3-5556-402c-b09b-6fddd139c608

📥 Commits

Reviewing files that changed from the base of the PR and between b018ec6 and 84154bb.

📒 Files selected for processing (1)
  • .github/workflows/dependency-review.yml

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Mtze
Mtze merged commit 8f507df into main Aug 27, 2026
6 checks passed
@Mtze
Mtze deleted the chore/dependency-review branch August 27, 2026 15:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant