Run integration connectivity check nightly to catch token expiry early (#208) #305
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Dependency Review Action | |
| # | |
| # This Action will scan dependency manifest files that change as part of a Pull Request, | |
| # surfacing known-vulnerable versions of the packages declared or updated in the PR. | |
| # Once installed, if the workflow run is marked as required, PRs introducing known-vulnerable | |
| # packages will be blocked from merging. | |
| # | |
| # Source repository: https://github.com/actions/dependency-review-action | |
| # Public documentation: https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review#dependency-review-enforcement | |
| name: 'Dependency review' | |
| on: | |
| # Use pull_request_target so the review also works for PRs opened from forks. | |
| # A plain `pull_request` run from a fork receives a read-only GITHUB_TOKEN, so | |
| # `comment-summary-in-pr` cannot post its summary ("Unable to write summary to | |
| # pull-request. Make sure you are giving this workflow the permission | |
| # 'pull-requests: write'"). pull_request_target runs in the base-repo context | |
| # with a read/write token, so the summary is posted on fork PRs too. | |
| # | |
| # This is safe here because dependency-review-action never checks out or executes | |
| # PR-supplied code: it only compares the PR's base/head via the GitHub | |
| # dependency-graph/advisory API. No checkout step is used, so untrusted code is | |
| # never run with the elevated token. | |
| pull_request_target: | |
| branches: [ "main" ] | |
| # Cancel superseded runs for the same PR to save runner minutes. | |
| concurrency: | |
| group: dependency-review-${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| # If using a dependency submission action in this workflow this permission will need to be set to: | |
| # | |
| # permissions: | |
| # contents: write | |
| # | |
| # https://docs.github.com/en/enterprise-cloud@latest/code-security/supply-chain-security/understanding-your-software-supply-chain/using-the-dependency-submission-api | |
| permissions: | |
| contents: read | |
| # Required so `comment-summary-in-pr` can post the review summary (works for | |
| # fork PRs only because of the pull_request_target trigger above). | |
| pull-requests: write | |
| jobs: | |
| dependency-review: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| steps: | |
| - name: 'Dependency Review' | |
| uses: actions/dependency-review-action@2031cfc080254a8a887f58cffee85186f0e49e48 # v4.9.0 | |
| # Commonly enabled options, see https://github.com/actions/dependency-review-action#configuration-options for all available options. | |
| with: | |
| comment-summary-in-pr: always | |
| # Fail the PR when it introduces a vulnerability at or above this severity. | |
| fail-on-severity: high | |
| # Block copyleft / incompatible licenses that conflict with this MIT project. | |
| deny-licenses: GPL-1.0-or-later, GPL-2.0-or-later, GPL-3.0-or-later, LGPL-2.0-or-later, LGPL-2.1-or-later, LGPL-3.0-or-later, AGPL-3.0-or-later | |
| # Snapshot dependency data can lag right after a push; retry instead of failing spuriously. | |
| retry-on-snapshot-warnings: true |