Skip to content

ci: add dependency-review action for vulnerability scanning#2471

Merged
yoshinorin merged 1 commit intomasterfrom
ci/add-dependencies-review
Apr 11, 2026
Merged

ci: add dependency-review action for vulnerability scanning#2471
yoshinorin merged 1 commit intomasterfrom
ci/add-dependencies-review

Conversation

@yoshinorin
Copy link
Copy Markdown
Member

@yoshinorin yoshinorin commented Jan 3, 2026

Check List

  • Others (Update, fix, translation, etc...)

Description

This PR adds a GitHub Actions workflow to check for vulnerabilities in dependencies when they are added or modified, and comments on the PR with the results. It detects changes to package.json and lockfiles.

Please see more info: hexojs/hexo-generator-feed#254

Additional information

After this PR is merged, I plan to pin dependencies and add a lockfile to this repository.

@github-actions github-actions Bot added the infra infrastructure, configuration of this repo label Jan 3, 2026
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Jan 3, 2026

✅ Theme thumbnails validation completed.

@yoshinorin yoshinorin merged commit 2547ce2 into master Apr 11, 2026
9 checks passed
@yoshinorin yoshinorin deleted the ci/add-dependencies-review branch April 11, 2026 00:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

infra infrastructure, configuration of this repo

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants