Skip to content
Merged
Changes from 1 commit
Commits
Show all changes
18 commits
Select commit Hold shift + click to select a range
8b42c49
feat: add dependency-scan GitHub Actions workflow
devin-ai-integration[bot] Sep 11, 2025
52ddeb0
Potential fix for code scanning alert no. 556: Workflow does not cont…
pkaeding Sep 11, 2025
a732ae6
fix: format dependency-scan.yml with prettier
devin-ai-integration[bot] Sep 11, 2025
3fe87dc
fix: format dependency-scan.yml with prettier
devin-ai-integration[bot] Sep 11, 2025
417bbf4
fix: add missing checkout step to evaluate-policy job
devin-ai-integration[bot] Sep 11, 2025
33da2ad
fix: add memory configuration for cdxgen in large monorepo
devin-ai-integration[bot] Sep 11, 2025
4c32bfe
fix: exclude rrweb submodule from SBOM generation to prevent timeout
devin-ai-integration[bot] Sep 11, 2025
5ead876
fix: use larger runner and full SBOM generation for complete dependen…
devin-ai-integration[bot] Sep 11, 2025
bcb96de
fix: use correct pinned SHA for actions/checkout@v4
devin-ai-integration[bot] Sep 11, 2025
86158bb
Merge branch 'main' into devin/1757599614-add-dependency-scan-workflow
kinyoklion Oct 6, 2025
e473ddd
fix: use ubuntu-latest runner as requested in PR review
devin-ai-integration[bot] Oct 7, 2025
5c80e65
fix: use reusable workflow with larger runner to resolve SBOM generat…
devin-ai-integration[bot] Oct 7, 2025
e9fcc8c
Potential fix for code scanning alert no. 583: Workflow does not cont…
pkaeding Oct 14, 2025
8f8e316
go back to shared actions
pkaeding Oct 14, 2025
aceb9b3
simplify workflow
pkaeding Oct 14, 2025
6fcdeb8
fix bomfile
pkaeding Oct 15, 2025
a16199e
lint
Vadman97 Oct 15, 2025
2d538fa
Merge branch 'main' into devin/1757599614-add-dependency-scan-workflow
pkaeding Oct 16, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 28 additions & 0 deletions .github/workflows/dependency-scan.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
name: Dependency Scan

on:
pull_request:
push:
branches:
- main

jobs:
generate-nodejs-sbom:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- name: Generate SBOM
uses: launchdarkly/gh-actions/actions/dependency-scan/generate-sbom@main
with:
types: 'nodejs'

evaluate-policy:
runs-on: ubuntu-latest
needs:
- generate-nodejs-sbom
steps:
- name: Evaluate SBOM Policy
uses: launchdarkly/gh-actions/actions/dependency-scan/evaluate-policy@main
with:
artifacts-pattern: bom-*
Loading