-
Notifications
You must be signed in to change notification settings - Fork 1
Closed
Labels
enhancementNew feature or improvementNew feature or improvementowner:agentAgent can complete autonomouslyAgent can complete autonomouslypriority:highHigh priorityHigh prioritystatus:planningTask is in planningTask is in planning
Milestone
Description
What needs to be done
Create .github/workflows/dependency-review.yml using actions/dependency-review-action (SHA-pinned). Runs on PRs, flags new dependencies with known vulnerabilities.
Acceptance Criteria
- Workflow exists with fail-on-severity: moderate
- Comments summary on PR
- SHA-pinned action
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
enhancementNew feature or improvementNew feature or improvementowner:agentAgent can complete autonomouslyAgent can complete autonomouslypriority:highHigh priorityHigh prioritystatus:planningTask is in planningTask is in planning