Skip to content

feat: align xarf-python with XARF v4 spec and JavaScript reference #4

feat: align xarf-python with XARF v4 spec and JavaScript reference

feat: align xarf-python with XARF v4 spec and JavaScript reference #4

name: 'Dependency Review'
on:
pull_request:
branches: [ main ]
permissions:
contents: read
pull-requests: write
jobs:
dependency-review:
name: Dependency Review
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Dependency Review
uses: actions/dependency-review-action@v4
with:
# Fail if vulnerabilities found
fail-on-severity: moderate
# Block banned licenses
deny-licenses: GPL-3.0, AGPL-3.0
# Comment on PR with details
comment-summary-in-pr: on-failure