Skip to content

build(deps): Bump the actions-dependencies group with 2 updates (#392) #1066

build(deps): Bump the actions-dependencies group with 2 updates (#392)

build(deps): Bump the actions-dependencies group with 2 updates (#392) #1066

name: 'Dependency Review'
on: [pull_request, push, workflow_dispatch]
permissions:
contents: read
pull-requests: write
# https://www.meziantou.net/how-to-cancel-github-workflows-when-pushing-new-commits-on-a-branch.htm
concurrency:
# pull request number or branch name if not a pull request
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
jobs:
dependency-review:
if: github.actor != 'dependabot[bot]'
runs-on: ubuntu-latest
steps:
- name: 'Checkout Repository'
uses: actions/[email protected]
- name: 'Dependency Review'
uses: actions/dependency-review-action@v4
with:
base-ref: master
head-ref: master
fail-on-severity: high
comment-summary-in-pr: always