mamasita[Actions]: bump docker/build-push-action from 5.1.0 to 6.0.1 #37
Workflow file for this run
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
# Dependency Review Action | |
# | |
# This Action will scan dependency manifest files that change as part of a Pull Request, | |
# surfacing known-vulnerable versions of the packages declared or updated in the PR. | |
# Once installed, if the workflow run is marked as required, PRs introducing known-vulnerable | |
# packages will be blocked from merging. | |
# | |
# Source repository: https://github.com/actions/dependency-review-action | |
# Public documentation: https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review#dependency-review-enforcement | |
name: 'Dependency review' | |
on: | |
pull_request: | |
branches: [ "main" ] #rama | |
permissions: # permisos | |
contents: read # Permite leer el contenido del repositorio | |
# Se necesitarán permisos de escritura para pull requests si se utiliza la opción `comment-summary-in-pr` en la acción `dependency-review-action`, coméntalo si no estás utilizando esta opción | |
pull-requests: write # Permite escribir pull request | |
jobs: | |
dependency-review: | |
runs-on: ubuntu-latest # Ejecuta una máquina virtual Ubuntu con la última versión disponible | |
steps: | |
- name: 'Checkout repository' | |
uses: actions/[email protected] # Utiliza checkout para clonar el repositorio | |
- name: 'Dependency Review' | |
uses: actions/dependency-review-action@v4 # Utiliza la acción para realizar la revisión de dependencias | |
with: | |
comment-summary-in-pr: always # Opción para incluir un resumen de comentarios en el pull request | |
config-file: './.github/dependency-review-config.yml' # Ubicación del archivo de configuración para la revisión de dependencias | |
# fail-on-severity: moderate | |
# deny-licenses: GPL-1.0-or-later, LGPL-2.0-or-later | |
# retry-on-snapshot-warnings: true |