Skip to content

Conversation

@Maosaic
Copy link
Collaborator

@Maosaic Maosaic commented Nov 25, 2025

Description

Add dependency review workflow action using Amazon OSPO default configuration

https://github.com/amazon-ospo/dependency-review-config/blob/main/default/dependency-review-config.yml

Issues Resolved

Screenshot

Screenshot 2025-11-25 at 12 26 03 PM

Testing the changes

Changelog

  • test: Add dependency review workflow action

Check List

  • All tests pass
    • yarn test:jest
    • yarn test:jest_integration
  • New functionality includes testing.
  • New functionality has been documented.
  • Update CHANGELOG.md
  • Commits are signed per the DCO using --signoff

@Maosaic Maosaic added OSD Changes being merged by the OSD team github_actions Pull requests that update GitHub Actions code labels Nov 25, 2025
@codecov
Copy link

codecov bot commented Nov 25, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 60.79%. Comparing base (f129a7e) to head (5b4aebb).

Additional details and impacted files
@@           Coverage Diff           @@
##             main   #10974   +/-   ##
=======================================
  Coverage   60.79%   60.79%           
=======================================
  Files        4531     4531           
  Lines      122258   122258           
  Branches    20498    20498           
=======================================
  Hits        74322    74322           
  Misses      42693    42693           
  Partials     5243     5243           
Flag Coverage Δ
Linux_1 26.56% <ø> (ø)
Linux_2 38.92% <ø> (ø)
Linux_3 39.50% <ø> (ø)
Linux_4 33.73% <ø> (ø)
Windows_1 26.57% <ø> (ø)
Windows_2 38.90% <ø> (ø)
Windows_3 39.50% <ø> (-0.01%) ⬇️
Windows_4 33.73% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

distinguished-contributor github_actions Pull requests that update GitHub Actions code OSD Changes being merged by the OSD team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants