Skip to content

Commit 14d6e75

Browse files
ci: harden dependency review workflow
1 parent c66246b commit 14d6e75

1 file changed

Lines changed: 3 additions & 1 deletion

File tree

.github/workflows/dependency-review.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,8 +27,10 @@ jobs:
2727
steps:
2828
- name: 'Checkout repository'
2929
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
30+
with:
31+
persist-credentials: false
3032
- name: 'Dependency Review'
31-
uses: actions/dependency-review-action@3c4e3dcb1aa7874d2c16be7d79418e9b7efd6261 # v4
33+
uses: actions/dependency-review-action@2031cfc080254a8a887f58cffee85186f0e49e48 # v4
3234
# Commonly enabled options, see https://github.com/actions/dependency-review-action#configuration-options for all available options.
3335
# No PR comment output to keep permissions read-only.
3436
# fail-on-severity: moderate

0 commit comments

Comments
 (0)