Add on-failure option to comment-summary-in-pr setting
This commit is contained in:
@@ -77,7 +77,7 @@ Configure this action by either inlining these options in your workflow file, or
|
|||||||
| `vulnerability-check` | Enable or disable the vulnerability check performed by the action. | `true`, `false` | `true` |
|
| `vulnerability-check` | Enable or disable the vulnerability check performed by the action. | `true`, `false` | `true` |
|
||||||
| `allow-dependencies-licenses`\* | Contains a list of packages that will be excluded from license checks. | Any package(s) in [purl](https://github.com/package-url/purl-spec) format | none |
|
| `allow-dependencies-licenses`\* | Contains a list of packages that will be excluded from license checks. | Any package(s) in [purl](https://github.com/package-url/purl-spec) format | none |
|
||||||
| `base-ref`/`head-ref` | Provide custom git references for the git base/head when performing the comparison check. This is only used for event types other than `pull_request` and `pull_request_target`. | Any valid git ref(s) in your project | none |
|
| `base-ref`/`head-ref` | Provide custom git references for the git base/head when performing the comparison check. This is only used for event types other than `pull_request` and `pull_request_target`. | Any valid git ref(s) in your project | none |
|
||||||
| `comment-summary-in-pr` | Enable or disable reporting the review summary as a comment in the pull request. If enabled, you must give the workflow or job permission `pull-requests: write`. | `true`, `false` | `false` |
|
| `comment-summary-in-pr` | Enable or disable reporting the review summary as a comment in the pull request. If enabled, you must give the workflow or job permission `pull-requests: write`. | `always`, `on-failure`, `never` | `never` |
|
||||||
|
|
||||||
\*not supported for use with GitHub Enterprise Server
|
\*not supported for use with GitHub Enterprise Server
|
||||||
|
|
||||||
|
|||||||
@@ -24,7 +24,7 @@ const defaultConfig: ConfigurationOptions = {
|
|||||||
allow_ghsas: [],
|
allow_ghsas: [],
|
||||||
allow_licenses: [],
|
allow_licenses: [],
|
||||||
deny_licenses: [],
|
deny_licenses: [],
|
||||||
comment_summary_in_pr: true
|
comment_summary_in_pr: 'never'
|
||||||
}
|
}
|
||||||
|
|
||||||
const changesWithEmptyManifests: Changes = [
|
const changesWithEmptyManifests: Changes = [
|
||||||
|
|||||||
+1
-1
@@ -45,7 +45,7 @@ inputs:
|
|||||||
description: A boolean to determine if vulnerability checks should be performed
|
description: A boolean to determine if vulnerability checks should be performed
|
||||||
required: false
|
required: false
|
||||||
comment-summary-in-pr:
|
comment-summary-in-pr:
|
||||||
description: A boolean to determine if the report should be posted as a comment in the PR itself. Setting this to true requires you to give the workflow the write permissions for pull-requests
|
description: Determines if the summary is posted as a comment in the PR itself. Setting this to `always` or `on-failure` requires you to give the workflow the write permissions for pull-requests
|
||||||
required: false
|
required: false
|
||||||
runs:
|
runs:
|
||||||
using: 'node16'
|
using: 'node16'
|
||||||
|
|||||||
+6
-4
@@ -527,7 +527,9 @@ function run() {
|
|||||||
}
|
}
|
||||||
summary.addScannedDependencies(changes);
|
summary.addScannedDependencies(changes);
|
||||||
printScannedDependencies(changes);
|
printScannedDependencies(changes);
|
||||||
if (config.comment_summary_in_pr) {
|
if (config.comment_summary_in_pr === 'always' ||
|
||||||
|
(config.comment_summary_in_pr === 'on-failure' &&
|
||||||
|
process.exitCode === core.ExitCode.Failure)) {
|
||||||
yield (0, comment_pr_1.commentPr)(core.summary);
|
yield (0, comment_pr_1.commentPr)(core.summary);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -717,7 +719,7 @@ exports.ConfigurationOptionsSchema = z
|
|||||||
config_file: z.string().optional(),
|
config_file: z.string().optional(),
|
||||||
base_ref: z.string().optional(),
|
base_ref: z.string().optional(),
|
||||||
head_ref: z.string().optional(),
|
head_ref: z.string().optional(),
|
||||||
comment_summary_in_pr: z.boolean().default(false)
|
comment_summary_in_pr: z.enum(['always', 'never', 'on-failure']).default('never'),
|
||||||
})
|
})
|
||||||
.superRefine((config, context) => {
|
.superRefine((config, context) => {
|
||||||
if (config.allow_licenses && config.deny_licenses) {
|
if (config.allow_licenses && config.deny_licenses) {
|
||||||
@@ -47826,7 +47828,7 @@ function readInlineConfig() {
|
|||||||
const vulnerability_check = getOptionalBoolean('vulnerability-check');
|
const vulnerability_check = getOptionalBoolean('vulnerability-check');
|
||||||
const base_ref = getOptionalInput('base-ref');
|
const base_ref = getOptionalInput('base-ref');
|
||||||
const head_ref = getOptionalInput('head-ref');
|
const head_ref = getOptionalInput('head-ref');
|
||||||
const comment_summary_in_pr = getOptionalBoolean('comment-summary-in-pr');
|
const comment_summary_in_pr = getOptionalInput('comment-summary-in-pr');
|
||||||
validatePURL(allow_dependencies_licenses);
|
validatePURL(allow_dependencies_licenses);
|
||||||
validateLicenses('allow-licenses', allow_licenses);
|
validateLicenses('allow-licenses', allow_licenses);
|
||||||
validateLicenses('deny-licenses', deny_licenses);
|
validateLicenses('deny-licenses', deny_licenses);
|
||||||
@@ -48124,7 +48126,7 @@ exports.ConfigurationOptionsSchema = z
|
|||||||
config_file: z.string().optional(),
|
config_file: z.string().optional(),
|
||||||
base_ref: z.string().optional(),
|
base_ref: z.string().optional(),
|
||||||
head_ref: z.string().optional(),
|
head_ref: z.string().optional(),
|
||||||
comment_summary_in_pr: z.boolean().default(false)
|
comment_summary_in_pr: z.enum(['always', 'never', 'on-failure']).default('never'),
|
||||||
})
|
})
|
||||||
.superRefine((config, context) => {
|
.superRefine((config, context) => {
|
||||||
if (config.allow_licenses && config.deny_licenses) {
|
if (config.allow_licenses && config.deny_licenses) {
|
||||||
|
|||||||
+1
-1
File diff suppressed because one or more lines are too long
+3
-3
@@ -161,7 +161,7 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
fail-on-severity: critical
|
fail-on-severity: critical
|
||||||
deny-licenses: LGPL-2.0, BSD-2-Clause
|
deny-licenses: LGPL-2.0, BSD-2-Clause
|
||||||
comment-summary-in-pr: true
|
comment-summary-in-pr: always
|
||||||
```
|
```
|
||||||
|
|
||||||
## Exclude dependencies from the license check
|
## Exclude dependencies from the license check
|
||||||
@@ -189,7 +189,7 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
fail-on-severity: critical
|
fail-on-severity: critical
|
||||||
deny-licenses: LGPL-2.0, BSD-2-Clause
|
deny-licenses: LGPL-2.0, BSD-2-Clause
|
||||||
comment-summary-in-pr: true
|
comment-summary-in-pr: always
|
||||||
allow-dependencies-licenses: 'pkg:npm/loadash, pkg:pip/requests'
|
allow-dependencies-licenses: 'pkg:npm/loadash, pkg:pip/requests'
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -227,6 +227,6 @@ jobs:
|
|||||||
uses: actions/dependency-review-action@v3
|
uses: actions/dependency-review-action@v3
|
||||||
with:
|
with:
|
||||||
fail-on-severity: critical
|
fail-on-severity: critical
|
||||||
comment-summary-in-pr: true
|
comment-summary-in-pr: always
|
||||||
license-check: false
|
license-check: false
|
||||||
```
|
```
|
||||||
|
|||||||
@@ -28,7 +28,7 @@ const defaultConfig: ConfigurationOptions = {
|
|||||||
'pkg:pip/certifi',
|
'pkg:pip/certifi',
|
||||||
'pkg:pip/[email protected]'
|
'pkg:pip/[email protected]'
|
||||||
],
|
],
|
||||||
comment_summary_in_pr: true
|
comment_summary_in_pr: 'never'
|
||||||
}
|
}
|
||||||
|
|
||||||
const tmpDir = path.resolve(__dirname, '../tmp')
|
const tmpDir = path.resolve(__dirname, '../tmp')
|
||||||
|
|||||||
+1
-1
@@ -38,7 +38,7 @@ function readInlineConfig(): ConfigurationOptionsPartial {
|
|||||||
const vulnerability_check = getOptionalBoolean('vulnerability-check')
|
const vulnerability_check = getOptionalBoolean('vulnerability-check')
|
||||||
const base_ref = getOptionalInput('base-ref')
|
const base_ref = getOptionalInput('base-ref')
|
||||||
const head_ref = getOptionalInput('head-ref')
|
const head_ref = getOptionalInput('head-ref')
|
||||||
const comment_summary_in_pr = getOptionalBoolean('comment-summary-in-pr')
|
const comment_summary_in_pr = getOptionalInput('comment-summary-in-pr')
|
||||||
|
|
||||||
validatePURL(allow_dependencies_licenses)
|
validatePURL(allow_dependencies_licenses)
|
||||||
validateLicenses('allow-licenses', allow_licenses)
|
validateLicenses('allow-licenses', allow_licenses)
|
||||||
|
|||||||
+5
-1
@@ -84,7 +84,11 @@ async function run(): Promise<void> {
|
|||||||
|
|
||||||
summary.addScannedDependencies(changes)
|
summary.addScannedDependencies(changes)
|
||||||
printScannedDependencies(changes)
|
printScannedDependencies(changes)
|
||||||
if (config.comment_summary_in_pr) {
|
if (
|
||||||
|
config.comment_summary_in_pr === 'always' ||
|
||||||
|
(config.comment_summary_in_pr === 'on-failure' &&
|
||||||
|
process.exitCode === core.ExitCode.Failure)
|
||||||
|
) {
|
||||||
await commentPr(core.summary)
|
await commentPr(core.summary)
|
||||||
}
|
}
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
|
|||||||
+1
-1
@@ -47,7 +47,7 @@ export const ConfigurationOptionsSchema = z
|
|||||||
config_file: z.string().optional(),
|
config_file: z.string().optional(),
|
||||||
base_ref: z.string().optional(),
|
base_ref: z.string().optional(),
|
||||||
head_ref: z.string().optional(),
|
head_ref: z.string().optional(),
|
||||||
comment_summary_in_pr: z.boolean().default(false)
|
comment_summary_in_pr: z.enum(['always', 'never', 'on-failure']).default('never'),
|
||||||
})
|
})
|
||||||
.superRefine((config, context) => {
|
.superRefine((config, context) => {
|
||||||
if (config.allow_licenses && config.deny_licenses) {
|
if (config.allow_licenses && config.deny_licenses) {
|
||||||
|
|||||||
Reference in New Issue
Block a user