瀏覽代碼

ci: Add audit for python dependencies via pip-audit

version-14
Gavin D'souza 3 年之前
committed by gavin
父節點
當前提交
593fd0a178
共有 1 個檔案被更改,包括 22 行新增0 行删除
  1. +22
    -0
      .github/workflows/deps-checker.yml

+ 22
- 0
.github/workflows/deps-checker.yml 查看文件

@@ -0,0 +1,22 @@
name: 'Python Dependency Check'
on:
pull_request:
workflow_dispatch:
push:
branches: [ develop ]

permissions:
contents: read

jobs:
deps-vulnerable-check:
name: 'Vulnerable Dependency'
runs-on: ubuntu-latest

steps:
- uses: actions/setup-python@v4
with:
python-version: 3.8
- uses: actions/checkout@v3
- run: pip install pip-audit
- run: pip-audit ${GITHUB_WORKSPACE}

Loading…
取消
儲存