Update README to include config-file option.
This commit is contained in:
@@ -70,6 +70,17 @@ or by inlining this option in your workflow file.
|
|||||||
|
|
||||||
### Options
|
### Options
|
||||||
|
|
||||||
|
#### config-file
|
||||||
|
|
||||||
|
**TODO**: Change this to be a user-configured string.
|
||||||
|
|
||||||
|
Defaults to `false`. Configure whether an external configuration file
|
||||||
|
will be used.
|
||||||
|
|
||||||
|
**Possible values**: `true`, `false`.
|
||||||
|
|
||||||
|
**Example**: `config-file: true`.
|
||||||
|
|
||||||
#### fail-on-severity
|
#### fail-on-severity
|
||||||
|
|
||||||
Configure the severity level for alerting. See "[Vulnerability Severity](https://github.com/actions/dependency-review-action#vulnerability-severity)".
|
Configure the severity level for alerting. See "[Vulnerability Severity](https://github.com/actions/dependency-review-action#vulnerability-severity)".
|
||||||
@@ -94,7 +105,6 @@ allow-licenses:
|
|||||||
- MIT
|
- MIT
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
||||||
#### deny-licenses
|
#### deny-licenses
|
||||||
|
|
||||||
Add a custom list of licenses you want to block. See
|
Add a custom list of licenses you want to block. See
|
||||||
@@ -129,10 +139,24 @@ head-ref: 69af5638bf660cf218aad5709a4c100e42a2f37b
|
|||||||
|
|
||||||
### Configuration File
|
### Configuration File
|
||||||
|
|
||||||
You can create a YAML file in
|
You can use an external configuration file to specify the settings for
|
||||||
`~/.github/dependency-review-config.yaml` to configure the
|
this Action.
|
||||||
action. **All of these fields are optional**. This is what a sample
|
|
||||||
file could look like:
|
Start by specifying that you will be using an external configuration
|
||||||
|
file:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- name: Dependency Review
|
||||||
|
uses: actions/dependency-review-action@v2
|
||||||
|
with:
|
||||||
|
config-file: true
|
||||||
|
```
|
||||||
|
|
||||||
|
**TODO**: Users should be able to provide a string for their config paths.
|
||||||
|
|
||||||
|
And then create the configuration file in
|
||||||
|
`~/.github/dependency-review-config.yaml`. **All of these fields are
|
||||||
|
optional**:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
fail-on-severity: "critical"
|
fail-on-severity: "critical"
|
||||||
@@ -140,8 +164,6 @@ allow-licenses:
|
|||||||
- "GPL-3.0"
|
- "GPL-3.0"
|
||||||
- "BSD-3-Clause"
|
- "BSD-3-Clause"
|
||||||
- "MIT"
|
- "MIT"
|
||||||
base-ref: "781a55e"
|
|
||||||
head-ref: "435083f"
|
|
||||||
```
|
```
|
||||||
|
|
||||||
### Inline Configuration
|
### Inline Configuration
|
||||||
|
|||||||
Reference in New Issue
Block a user