Skip to content

chore(ci): fail PRs that introduce vulnerable dependencies - #198

Merged
Mtze merged 1 commit into
mainfrom
chore/dependency-review
Aug 27, 2026
Merged

Mtze merged 1 commit into
mainfrom
chore/dependency-review

Conversation

@Mtze

@Mtze Mtze commented Aug 27, 2026

Copy link
Copy Markdown
Member

What and why

Renovate already tells us about vulnerable dependencies sitting on main. Nothing stopped a PR from adding a new one.

This wires up the shared reusable workflow EduIDE/.github/.github/workflows/dependency-review.yml@v1. It runs actions/dependency-review-action over the PR diff and fails the check when the PR introduces a dependency with a known advisory at high severity or above (the reusable workflow's default). It only looks at what the PR adds, so pre-existing findings do not block anyone.

There is no general-purpose CI workflow here - build.yml, package.yml and codeql.yml are each single-purpose - so this lands as its own .github/workflows/dependency-review.yml, triggered on PRs to main to match the others.

How it was verified

  • actionlint 1.7.6 run over this repo's workflows. The file changed here is clean. Pre-existing findings in workflows this PR does not touch were left alone.
  • This PR is itself the first run of the check - see the dependency-review entry in the checks list. It adds no dependencies, so it is expected to pass.
  • The underlying API needs the repo to be public (or GitHub Advanced Security on a private repo). This repo is public.

Deployment impact

  • Requires a config or secret change
  • Requires a migration
  • Changes a published artifact or image
  • CI-only change, no runtime impact

Risk and rollback

Low. The change adds a read-only PR check and touches nothing that ships. The one way it can bite: a PR that legitimately needs a dependency carrying a high-severity advisory gets blocked until the dependency is upgraded or swapped.

Rollback: revert this commit. To soften it instead, pass a higher fail-on-severity to the reusable workflow.

Adds a Dependency Review workflow that calls the shared EduIDE/.github
reusable workflow. It fails a PR that introduces a dependency with a known
advisory at high severity or above, and stays quiet about anything already on
main.

The repo has no general-purpose CI workflow, so this lands as its own
single-purpose file, matching how the other checks here are organised.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9
@coderabbitai

coderabbitai Bot commented Aug 27, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 31 minutes.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 675343e1-3cee-4e10-acdf-8e23b1094078

📥 Commits

Reviewing files that changed from the base of the PR and between f0ac88c and a00c746.

📒 Files selected for processing (1)
  • .github/workflows/dependency-review.yml

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.


jobs:
dependency-review:
uses: EduIDE/.github/.github/workflows/dependency-review.yml@v1
@Mtze
Mtze merged commit 72ec2e6 into main Aug 27, 2026
8 checks passed
@Mtze
Mtze deleted the chore/dependency-review branch August 27, 2026 15:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants