瀏覽代碼

Add dependency review step to workflows

arkon 3 年之前
父節點
當前提交
07a9fd061d
共有 2 個文件被更改,包括 14 次插入2 次删除
  1. 7 1
      .github/workflows/build_pull_request.yml
  2. 7 1
      .github/workflows/build_push.yml

+ 7 - 1
.github/workflows/build_pull_request.yml

@@ -5,6 +5,9 @@ on:
       - '**.md'
       - 'app/src/main/res/**/strings.xml'
 
+permissions:
+  contents: read
+
 jobs:
   build:
     name: Build app
@@ -12,11 +15,14 @@ jobs:
 
     steps:
       - name: Clone repo
-        uses: actions/checkout@v2
+        uses: actions/checkout@v3
 
       - name: Validate Gradle Wrapper
         uses: gradle/wrapper-validation-action@v1
 
+      - name: Dependency Review
+        uses: actions/dependency-review-action@v1
+
       - name: Set up JDK 11
         uses: actions/setup-java@v1
         with:

+ 7 - 1
.github/workflows/build_push.yml

@@ -6,6 +6,9 @@ on:
     tags:
       - v*
 
+permissions:
+  contents: read
+
 jobs:
   build:
     name: Build app
@@ -19,11 +22,14 @@ jobs:
           all_but_latest: true
 
       - name: Clone repo
-        uses: actions/checkout@v2
+        uses: actions/checkout@v3
 
       - name: Validate Gradle Wrapper
         uses: gradle/wrapper-validation-action@v1
 
+      - name: Dependency Review
+        uses: actions/dependency-review-action@v1
+
       - name: Set up JDK 11
         uses: actions/setup-java@v1
         with: