From 84154bb15a91dafea1e13fac3b362183f2444c5e Mon Sep 17 00:00:00 2001 From: Matthias Linhuber Date: Thu, 27 Aug 2026 17:45:27 +0200 Subject: [PATCH] chore(ci): add dependency review to PR CI Renovate reports advisories on dependencies we already have. This adds the org-wide dependency-review check, which looks only at what a PR introduces and fails on a newly added advisory of high severity or above. It gets its own workflow file: the existing PR-triggered workflows are path filtered to src/ and chart/, and this should run on every PR. The Go module lives in src/ rather than the repo root. GitHub's dependency graph already indexes it, and the action reads the graph rather than the checkout, so no extra configuration is needed. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9 --- .github/workflows/dependency-review.yml | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) create mode 100644 .github/workflows/dependency-review.yml diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml new file mode 100644 index 0000000..930fdca --- /dev/null +++ b/.github/workflows/dependency-review.yml @@ -0,0 +1,20 @@ +# Renovate tells us about vulnerabilities we already have. This catches the +# ones a PR is about to add: it diffs the PR's dependencies against main and +# fails on a newly introduced advisory of high severity or above. +# +# The Go module lives in src/, which GitHub's dependency graph picks up on its +# own - the action reads the graph, not the checkout. +# +# The grammar lives in EduIDE/.github so the repos cannot drift apart on it. + +name: Dependency Review + +on: + pull_request: + +permissions: + contents: read + +jobs: + dependency-review: + uses: EduIDE/.github/.github/workflows/dependency-review.yml@v1