Skip to content

Remediate OpenSSF Scorecard pinned-dependencies #36

Remediate OpenSSF Scorecard pinned-dependencies

Remediate OpenSSF Scorecard pinned-dependencies #36

name: Dependency review
on:
pull_request:
branches:
- main
jobs:
dependency-review:
runs-on: ubuntu-latest
permissions:
pull-requests: write
steps:
- name: Checkout repository
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
- name: Dependency review
uses: actions/dependency-review-action@9129d7d40b8c12c1ed0f60400d00c92d437adcce # v4.1.3
with:
comment-summary-in-pr: true
fail-on-severity: low
vulnerability-check: true