Skip to content

Bump the github group with 6 updates #7

Bump the github group with 6 updates

Bump the github group with 6 updates #7

name: dependency-review
on:
pull_request:
permissions:
contents: none
pull-requests: none
jobs:
dependency-review:
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: write
steps:
- name: 🔒 harden runner
uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
with:
egress-policy: audit
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
- name: 🔂 dependency review
uses: actions/dependency-review-action@3b139cfc5fae8b618d3eae3675e383bb1769c019 # v4.5.0
with:
deny-licenses: AGPL-3.0
fail-on-severity: moderate
comment-summary-in-pr: true