8000 feat: add dependency review tool by UlisesGascon · Pull Request #6031 · lodash/lodash · GitHub
[go: up one dir, main page]

Skip to content

Conversation

@UlisesGascon
Copy link
Member

Main Changes

This workflow will run dependency-review-action on every PR to detect vulnerable dependencies and invalid licenses

Context

Related to #6027

@jdalton
Copy link
Member
jdalton commented Oct 27, 2025

@UlisesGascon Thank you! I think this is a perfect one for Socket.dev. Let's hold this PR and nitpick it a bit.

@UlisesGascon
Copy link
Member Author

Converting this to draft while we review and refine the details.

@UlisesGascon UlisesGascon marked this pull request as draft October 27, 2025 20:30
@UlisesGascon UlisesGascon added the STA-2025 Issues and tasks related to the work funded by STA for Q4 2025. label Nov 7, 2025
@UlisesGascon UlisesGascon self-assigned this Nov 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

STA-2025 Issues and tasks related to the work funded by STA for Q4 2025.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

0