diff --git a/README.md b/README.md index 9ae9f91..37a36dd 100644 --- a/README.md +++ b/README.md @@ -1,17 +1,32 @@ # dependency-review-action -This action scans your pull requests for dependency changes, and will -raise an error if any vulnerabilities or invalid licenses are being introduced. The action is supported by an [API endpoint](https://docs.github.com/rest/dependency-graph/dependency-review) that diffs the dependencies between any two revisions on your default branch. +- [Overview](#overview) +- [Installation](#installation) +- [Configuration](#configuration) -The action is available for all public repositories, as well as private repositories that have GitHub Advanced Security licensed. +- [Outputs](#outputs) +- [Getting help](#getting-help) +- [Contributing](#contributing) +- [License](#license) -You can see the results on the job logs: +## Overview -GitHub workflow run log showing Dependency Review job output +The dependency review action scans your pull requests for dependency changes, and will raise an error if any vulnerabilities or invalid licenses are being introduced. +The action is supported by an [API endpoint](https://docs.github.com/en/rest/dependency-graph/dependency-review?apiVersion=2022-11-28) that diffs the dependencies between any two revisions on your default branch. -or on the job summary: +When the action runs, you can see the results on: -GitHub job summary showing Dependency Review output +- The **job logs**, found .... + + GitHub workflow run log showing Dependency Review job output + +- The **job summary**, found .... + + GitHub job summary showing Dependency Review output + +The action is available for: +- Public repositories +- Private repositories with a [GitHub Advanced Security](https://docs.github.com/en/enterprise-cloud@latest/get-started/learning-about-github/about-github-advanced-security) license. ## Installation