chore(ci): fail PRs that introduce vulnerable dependencies - #198
Merged
Merged
Conversation
Adds a Dependency Review workflow that calls the shared EduIDE/.github reusable workflow. It fails a PR that introduces a dependency with a known advisory at high severity or above, and stays quiet about anything already on main. The repo has no general-purpose CI workflow, so this lands as its own single-purpose file, matching how the other checks here are organised. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9
|
Warning Review limit reachedNext included review available in 31 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
|
||
| jobs: | ||
| dependency-review: | ||
| uses: EduIDE/.github/.github/workflows/dependency-review.yml@v1 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
Renovate already tells us about vulnerable dependencies sitting on
main. Nothing stopped a PR from adding a new one.This wires up the shared reusable workflow
EduIDE/.github/.github/workflows/dependency-review.yml@v1. It runsactions/dependency-review-actionover the PR diff and fails the check when the PR introduces a dependency with a known advisory at high severity or above (the reusable workflow's default). It only looks at what the PR adds, so pre-existing findings do not block anyone.There is no general-purpose CI workflow here -
build.yml,package.ymlandcodeql.ymlare each single-purpose - so this lands as its own.github/workflows/dependency-review.yml, triggered on PRs tomainto match the others.How it was verified
actionlint1.7.6 run over this repo's workflows. The file changed here is clean. Pre-existing findings in workflows this PR does not touch were left alone.dependency-reviewentry in the checks list. It adds no dependencies, so it is expected to pass.Deployment impact
Risk and rollback
Low. The change adds a read-only PR check and touches nothing that ships. The one way it can bite: a PR that legitimately needs a dependency carrying a high-severity advisory gets blocked until the dependency is upgraded or swapped.
Rollback: revert this commit. To soften it instead, pass a higher
fail-on-severityto the reusable workflow.