Skip to content

Conversation

inigomarquinez
Copy link
Contributor

Main Changes

This GitHub action will add an additional check when a PR is created in the project and will review any change in the dependencies.

This Action will scan dependency manifest files that change as part of a Pull Request, surfacing known-vulnerable versions of the packages declared or updated in the PR. Once installed, if the workflow run is marked as required, PRs introducing known-vulnerable packages will be blocked from merging.
Source repository

Overall, this will prevent us from introducing vulnerable dependencies versions without the need to manually check that.

Impact in the OSSF Scorecard

Captura de pantalla 2024-03-14 a las 21 38 51

Note that our current score is 10/10, so this is a preventive measurement.

Context

Copy link
Member

@UlisesGascon UlisesGascon left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@UlisesGascon UlisesGascon merged commit b7b21ff into jshttp:master Feb 13, 2025
@UlisesGascon UlisesGascon mentioned this pull request Jun 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants