8000 add community-wide reusable workflow for license/vuln scan (#255) · tetsuo-cpp/sigstore-python@1d34982 · GitHub
[go: up one dir, main page]

Skip to content

Commit 1d34982

Browse files
bobcallawaydi
andauthored
add community-wide reusable workflow for license/vuln scan (sigstore#255)
Signed-off-by: Bob Callaway <bcallaway@google.com> Signed-off-by: Bob Callaway <bcallaway@google.com> Co-authored-by: Dustin Ingram <di@users.noreply.github.com>
1 parent 315b078 commit 1d34982

File tree

1 file changed

+24
-0
lines changed

1 file changed

+24
-0
lines changed

.github/workflows/depsreview.yml

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
#
2+
# Copyright 2022 The Sigstore Authors.
3+
#
4+
# Licensed under the Apache License, Version 2.0 (the "License");
5+
# you may not use this file except in compliance with the License.
6+
# You may obtain a copy of the License at
7+
#
8+
# http://www.apache.org/licenses/LICENSE-2.0
9+
#
10+
# Unless required by applicable law or agreed to in writing, software
11+
# distributed under the License is distributed on an "AS IS" BASIS,
12+
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13+
# See the License for the specific language governing permissions and
14+
# limitations under the License.
15+
name: 'Dependency Review'
16+
on: [pull_request]
17+
18+
permissions:
19+
contents: read
20+
21+
jobs:
22+
dependency-review:
23+
name: License and Vulnerability Scan
24+
uses: sigstore/community/.github/workflows/reusable-dependency-review.yml@9b1b5aca605f92ec5b1bf3681b1e61b3dbc420cc

0 commit comments

Comments
 (0)
0