Add dependency review

This commit is contained in:
dolorsfg 2024-06-13 15:58:23 +02:00 committed by GitHub
parent 9b1cd20833
commit b01b8bded2
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -28,5 +28,13 @@ jobs:
cache: maven
- name: Submit Dependency Snapshot
uses: advanced-security/maven-dependency-submission-action@v3
- name: Dependency review:
uses: actions/dependency-review-action@v4
# Commonly enabled options, see https://github.com/actions/dependency-review-action#configuration-options for all available options.
with:
comment-summary-in-pr: always
fail-on-severity: high
deny-licenses: GPL-1.0-or-later, LGPL-2.0-or-later
# retry-on-snapshot-warnings: true
- name: Build with Maven Wrapper
run: ./mvnw -B package