Skip to content

feat: add workflow js-dependency-audit.yaml#168

Merged
marians merged 3 commits into
mainfrom
add-npm-audit-workflow
May 12, 2026
Merged

feat: add workflow js-dependency-audit.yaml#168
marians merged 3 commits into
mainfrom
add-npm-audit-workflow

Conversation

@marians
Copy link
Copy Markdown
Member

@marians marians commented May 12, 2026

This PR adds a reusable workflow to audit JavaScript/TypeScript dependencies for security vulnerabilities in pull requests. It will comment into the PR, focussing on changes in vulnerabilities.

Tests

Note: both test PRs have been crafted to trigger the workflow. The happa one would normally not have triggered, as it didn't modify dependencies.

Checklist

  • I have updated the CHANGELOG.md with a description of the change

@marians marians marked this pull request as ready for review May 12, 2026 11:59
@marians marians requested a review from a team as a code owner May 12, 2026 11:59
Copy link
Copy Markdown

@lyind lyind left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me (as in "I think this mitigation/enhancement doesn't add new problems") 😆

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants