mirror of https://github.com/garrytan/gstack.git
gstack ships dependency-bearing manifests (package.json, bun.lock) but has no pull-request gate that blocks newly introduced known-vulnerable dependencies. A PR can currently add or bump an npm/Bun dependency with no CI check against advisories. Add a Dependency Review workflow using GitHub's official actions/dependency-review-action, which diffs the dependency graph (base...head) on each pull request and fails when a change introduces a dependency with a high or critical advisory. The threshold is documented inline and easy to tighten to moderate/low. Matches existing workflow house style (ubicloud-standard-8 runner, version- tagged actions, minimal contents:read permissions). Validated with actionlint 1.7.12 (the same linter run by .github/workflows/actionlint.yml): no issues. Fixes #1987 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| actionlint.yml | ||
| ci-image.yml | ||
| dependency-review.yml | ||
| evals-periodic.yml | ||
| evals.yml | ||
| make-pdf-gate.yml | ||
| pr-title-sync.yml | ||
| skill-docs.yml | ||
| version-gate.yml | ||
| windows-free-tests.yml | ||
| windows-setup-e2e.yml | ||