From a00c74675bf7bfcc02e4f6cfa0292667419458ec Mon Sep 17 00:00:00 2001 From: Matthias Linhuber Date: Thu, 27 Aug 2026 17:44:54 +0200 Subject: [PATCH] chore(ci): fail PRs that introduce vulnerable dependencies Adds a Dependency Review workflow that calls the shared EduIDE/.github reusable workflow. It fails a PR that introduces a dependency with a known advisory at high severity or above, and stays quiet about anything already on main. The repo has no general-purpose CI workflow, so this lands as its own single-purpose file, matching how the other checks here are organised. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9 --- .github/workflows/dependency-review.yml | 14 ++++++++++++++ 1 file changed, 14 insertions(+) create mode 100644 .github/workflows/dependency-review.yml diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml new file mode 100644 index 0000000..e927aa1 --- /dev/null +++ b/.github/workflows/dependency-review.yml @@ -0,0 +1,14 @@ +# Renovate reports vulnerabilities already on main; this one blocks a PR that +# is about to add a new dependency with a known advisory. It only looks at what +# the PR adds, so it stays quiet about pre-existing findings. + +name: Dependency Review + +on: + pull_request: + branches: + - main + +jobs: + dependency-review: + uses: EduIDE/.github/.github/workflows/dependency-review.yml@v1