Files
alfresco-ng2-components/.github/workflows/supply-chain-pr-instructions.yml

32 lines
887 B
YAML

name: Supply Chain Review - PR Instructions
on:
pull_request:
types: [opened, reopened, synchronize]
paths:
- "package.json"
- "pnpm-lock.yaml"
- "**/package.json"
- "pom.xml"
- "**/pom.xml"
jobs:
instructions:
runs-on: ubuntu-latest
permissions:
pull-requests: write
steps:
- uses: Alfresco/alfresco-build-tools/.github/actions/github-upsert-comment@a6a8be7429080c132815d0482a55ae4fd28f15ba # v18.7.0
with:
comment-identifier: supply-chain-review-instructions
comment-body: |
## 🔒 Supply Chain Security
This PR modifies dependencies. To run a security analysis, comment:
```
/supply-chain-review
```
The analysis will check for vulnerabilities, typosquatting, maintainer takeovers, and other supply chain risks.