Skip to content

feat(assail): exclude vendored-snapshot dirs (.yarn, idaptik-rescript13-staging, rescript-ecosystem) from analysis #90

feat(assail): exclude vendored-snapshot dirs (.yarn, idaptik-rescript13-staging, rescript-ecosystem) from analysis

feat(assail): exclude vendored-snapshot dirs (.yarn, idaptik-rescript13-staging, rescript-ecosystem) from analysis #90

# SPDX-License-Identifier: MPL-2.0
name: Dependency Review
on:
pull_request:
branches: [ main ]
permissions:
contents: read
pull-requests: write
jobs:
review:
name: Review Dependencies
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5
- name: Dependency Review
uses: actions/dependency-review-action@5a2ce3f5b92ee19cbb1541a4984c76d921601d7c # v4
with:
fail-on-severity: moderate