From 9a6781fe2a3bec4b57e6f1ec650fd15ef411ef4a Mon Sep 17 00:00:00 2001 From: Di Wu Date: Wed, 9 Aug 2023 17:54:44 -0700 Subject: [PATCH 1/2] ci: add dependency review workflow --- .github/workflows/dependency-review.yml | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) create mode 100644 .github/workflows/dependency-review.yml diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml new file mode 100644 index 0000000..85fa23e --- /dev/null +++ b/.github/workflows/dependency-review.yml @@ -0,0 +1,24 @@ +name: Dependency Review + +on: + pull_request: + branches: + - main + +permissions: + contents: read + +jobs: + dependency-review: + name: Dependency Review + runs-on: ubuntu-latest + steps: + - name: Checkout Code + uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3 + with: + persist-credentials: false + + - name: Dependency Review + uses: actions/dependency-review-action@7d90b4f05fea31dde1c4a1fb3fa787e197ea93ab # v3.0.7 + with: + config-file: aws-amplify/amplify-ci-support/.github/dependency-review-config.yml@5d/dependency-review From b1bc44489c9f3046e37047e2cb2c3cdc36be7fbd Mon Sep 17 00:00:00 2001 From: Di Wu Date: Thu, 14 Sep 2023 13:45:01 -0700 Subject: [PATCH 2/2] Update dependency-review.yml --- .github/workflows/dependency-review.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 85fa23e..27ebe3b 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -21,4 +21,4 @@ jobs: - name: Dependency Review uses: actions/dependency-review-action@7d90b4f05fea31dde1c4a1fb3fa787e197ea93ab # v3.0.7 with: - config-file: aws-amplify/amplify-ci-support/.github/dependency-review-config.yml@5d/dependency-review + config-file: aws-amplify/amplify-ci-support/.github/dependency-review-config.yml@main