mirror of
https://github.com/MichMich/MagicMirror.git
synced 2026-06-09 03:34:51 +00:00
*This type of runner is optimized for automation tasks, issue operations and short-running jobs. They are not suitable for typical heavyweight CI/CD builds.* [[1](https://docs.github.com/en/actions/reference/runners/github-hosted-runners#single-cpu-runners)]. We are not necessarily dependent on faster startups, but that seems to be becoming the best practice now.
19 lines
526 B
YAML
19 lines
526 B
YAML
# This workflow scans your pull requests for dependency changes, and will raise an error if any vulnerabilities or invalid licenses are being introduced.
|
|
# For more information see: https://github.com/actions/dependency-review-action
|
|
|
|
name: "Review Dependencies"
|
|
|
|
on: [pull_request]
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
dependency-review:
|
|
runs-on: ubuntu-slim
|
|
steps:
|
|
- name: "Checkout code"
|
|
uses: actions/checkout@v6
|
|
- name: "Dependency Review"
|
|
uses: actions/dependency-review-action@v4
|