Skip to content

ci: add CodeQL + OWASP Dependency-Check, attach SBOM and attestations to releases #1

ci: add CodeQL + OWASP Dependency-Check, attach SBOM and attestations to releases

ci: add CodeQL + OWASP Dependency-Check, attach SBOM and attestations to releases #1

name: Dependency Review
on:
pull_request:
branches: [main]
permissions:
contents: read
pull-requests: write
jobs:
dependency-review:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v6
- name: Dependency review
uses: actions/dependency-review-action@v5
with:
fail-on-severity: moderate
license-check: false
comment-summary-in-pr: on-failure