From 48e56cde7044fe1197b1be5474f6eca02ffdef38 Mon Sep 17 00:00:00 2001 From: Ivan Goncharov Date: Tue, 16 Aug 2022 14:50:26 +0300 Subject: [PATCH] ci: add dependency review workflow Motivation: increase security. Discovered while looking into #3162 --- .github/workflows/pull_request.yml | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/.github/workflows/pull_request.yml b/.github/workflows/pull_request.yml index 3fd1eeee26..3143dc1eb0 100644 --- a/.github/workflows/pull_request.yml +++ b/.github/workflows/pull_request.yml @@ -4,6 +4,18 @@ jobs: ci: uses: ./.github/workflows/ci.yml + dependency-review: + name: Security check of added dependencies + runs-on: ubuntu-latest + steps: + - name: Checkout repo + uses: actions/checkout@v3 + with: + persist-credentials: false + + - name: Dependency review + uses: actions/dependency-review-action@v2 + diff-npm-package: name: Diff content of NPM package runs-on: ubuntu-latest