update readme with notes on dependency scopes
This commit is contained in:
@@ -50,7 +50,6 @@ with the label of any of your runners (the default label
|
|||||||
is `self-hosted`):
|
is `self-hosted`):
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
|
|
||||||
# ...
|
# ...
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
@@ -86,6 +85,9 @@ jobs:
|
|||||||
# Possible values: "critical", "high", "moderate", "low"
|
# Possible values: "critical", "high", "moderate", "low"
|
||||||
# fail-on-severity: critical
|
# fail-on-severity: critical
|
||||||
#
|
#
|
||||||
|
# Possible values in comma separated list: "unknown", "runtime", or "development"
|
||||||
|
# fail-on-scopes: runtime, development
|
||||||
|
#
|
||||||
# Possible values: Any available git ref
|
# Possible values: Any available git ref
|
||||||
# base-ref: ${{ github.event.pull_request.base.ref }}
|
# base-ref: ${{ github.event.pull_request.base.ref }}
|
||||||
# head-ref: ${{ github.event.pull_request.head.ref }}
|
# head-ref: ${{ github.event.pull_request.head.ref }}
|
||||||
@@ -120,6 +122,17 @@ This example will only fail on pull requests with `critical` and `high` vulnerab
|
|||||||
fail-on-severity: high
|
fail-on-severity: high
|
||||||
```
|
```
|
||||||
|
|
||||||
|
### Dependency Scoping
|
||||||
|
|
||||||
|
By default the action will only fail on `runtime` dependencies that have vulnerabilities or unacceptable licenses, ignoring `development` dependencies. You can override this behavior with the `fail-on-scopes` option, which will allow you to list the specific dependency scopes you care about. The possible values are: `unknown`, `runtime`, and `development`. Note: Filtering by scope will not be supported on GHES just yet, as the REST API's introduction of `scope` will be released in an upcoming version.
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- name: Dependency Review
|
||||||
|
uses: actions/dependency-review-action@v2
|
||||||
|
with:
|
||||||
|
fail-on-scopes: runtime, development
|
||||||
|
```
|
||||||
|
|
||||||
### Licenses
|
### Licenses
|
||||||
|
|
||||||
You can set the action to fail on pull requests based on the licenses of the dependencies
|
You can set the action to fail on pull requests based on the licenses of the dependencies
|
||||||
@@ -150,14 +163,14 @@ to filter. A couple of examples:
|
|||||||
|
|
||||||
**Important**
|
**Important**
|
||||||
|
|
||||||
* Checking for licenses is not supported on GHES.
|
- Checking for licenses is not supported on GHES.
|
||||||
* The action will only accept one of the two parameters; an error will
|
- The action will only accept one of the two parameters; an error will
|
||||||
be raised if you provide both.
|
be raised if you provide both.
|
||||||
* By default both parameters are empty (no license checking is
|
- By default both parameters are empty (no license checking is
|
||||||
performed).
|
performed).
|
||||||
* We don't have license information for all of your dependents. If we
|
- We don't have license information for all of your dependents. If we
|
||||||
can't detect the license for a dependency **we will inform you, but the
|
can't detect the license for a dependency **we will inform you, but the
|
||||||
action won't fail**.
|
action won't fail**.
|
||||||
|
|
||||||
## Blocking pull requests
|
## Blocking pull requests
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user