Skip to content

Run integration connectivity check nightly to catch token expiry early (#208) #305

Run integration connectivity check nightly to catch token expiry early (#208)

Run integration connectivity check nightly to catch token expiry early (#208) #305

# Dependency Review Action
#
# This Action will scan dependency manifest files that change as part of a Pull Request,
# surfacing known-vulnerable versions of the packages declared or updated in the PR.
# Once installed, if the workflow run is marked as required, PRs introducing known-vulnerable
# packages will be blocked from merging.
#
# Source repository: https://github.com/actions/dependency-review-action
# Public documentation: https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review#dependency-review-enforcement
name: 'Dependency review'
on:
# Use pull_request_target so the review also works for PRs opened from forks.
# A plain `pull_request` run from a fork receives a read-only GITHUB_TOKEN, so
# `comment-summary-in-pr` cannot post its summary ("Unable to write summary to
# pull-request. Make sure you are giving this workflow the permission
# 'pull-requests: write'"). pull_request_target runs in the base-repo context
# with a read/write token, so the summary is posted on fork PRs too.
#
# This is safe here because dependency-review-action never checks out or executes
# PR-supplied code: it only compares the PR's base/head via the GitHub
# dependency-graph/advisory API. No checkout step is used, so untrusted code is
# never run with the elevated token.
pull_request_target:
branches: [ "main" ]
# Cancel superseded runs for the same PR to save runner minutes.
concurrency:
group: dependency-review-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
# If using a dependency submission action in this workflow this permission will need to be set to:
#
# permissions:
# contents: write
#
# https://docs.github.com/en/enterprise-cloud@latest/code-security/supply-chain-security/understanding-your-software-supply-chain/using-the-dependency-submission-api
permissions:
contents: read
# Required so `comment-summary-in-pr` can post the review summary (works for
# fork PRs only because of the pull_request_target trigger above).
pull-requests: write
jobs:
dependency-review:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: 'Dependency Review'
uses: actions/dependency-review-action@2031cfc080254a8a887f58cffee85186f0e49e48 # v4.9.0
# Commonly enabled options, see https://github.com/actions/dependency-review-action#configuration-options for all available options.
with:
comment-summary-in-pr: always
# Fail the PR when it introduces a vulnerability at or above this severity.
fail-on-severity: high
# Block copyleft / incompatible licenses that conflict with this MIT project.
deny-licenses: GPL-1.0-or-later, GPL-2.0-or-later, GPL-3.0-or-later, LGPL-2.0-or-later, LGPL-2.1-or-later, LGPL-3.0-or-later, AGPL-3.0-or-later
# Snapshot dependency data can lag right after a push; retry instead of failing spuriously.
retry-on-snapshot-warnings: true