diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml new file mode 100644 index 0000000..35b781f --- /dev/null +++ b/.github/workflows/dependency-review.yml @@ -0,0 +1,14 @@ +on: + pull_request: + branches: [main] + +permissions: {} + +jobs: + dependency-review: + runs-on: ubuntu-latest + permissions: + contents: read + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 + - uses: actions/dependency-review-action@ce3cf9537a52e8119d91fd484ab5b8a807627bf8 # v4.6.0 diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index b55b647..be1bd8d 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -17,3 +17,6 @@ jobs: with: go-version: 1.25.x - run: go test -race ./... + - uses: golang/govulncheck-action@b625fbe08f3bccbe446d94fbf87fcc875a4f50ee # v1.0.4 + with: + repo-checkout: false