Skip to content

ci: add dependency-review action for vulnerability scanning#153

Merged
yoshinorin merged 2 commits into
hexojs:masterfrom
yoshinorin:chore/ci/add-dependencies-review
May 10, 2026
Merged

ci: add dependency-review action for vulnerability scanning#153
yoshinorin merged 2 commits into
hexojs:masterfrom
yoshinorin:chore/ci/add-dependencies-review

Conversation

@yoshinorin
Copy link
Copy Markdown
Member

check list

  • Add test cases for the changes.
  • Passed the CI test.

Description

This PR adds a GitHub Actions workflow to check for vulnerabilities in dependencies when they are added or modified, and comments on the PR with the results. It detects changes to package.json and lockfiles.

refs: hexojs/hexo#5734

Additional information

N/A

@yoshinorin yoshinorin self-assigned this May 7, 2026
@yoshinorin
Copy link
Copy Markdown
Member Author

Pending #152

@yoshinorin yoshinorin marked this pull request as draft May 7, 2026 14:04
@yoshinorin yoshinorin marked this pull request as ready for review May 10, 2026 12:19
@yoshinorin yoshinorin merged commit b922861 into hexojs:master May 10, 2026
8 checks passed
@yoshinorin yoshinorin deleted the chore/ci/add-dependencies-review branch May 10, 2026 12:20
@coveralls
Copy link
Copy Markdown

Coverage Status

coverage: 100.0%. remained the same — yoshinorin:chore/ci/add-dependencies-review into hexojs:master

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants