Skip to content

Conversation

@mumoshu
Copy link
Collaborator

@mumoshu mumoshu commented Dec 16, 2025

This adds the dependency-review-action to the test workflow for automated dependency reviewing.

Please see https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review#about-the-dependency-review-action for more information on the action.

This adds the dependency-review-action to the test workflow for automated dependency reviewing.

Please see https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review#about-the-dependency-review-action for more information on the action.
push:
branches:
- 'main'
pull_request_target:
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would like to confirm the intention behind using pull_request_target!

If the purpose is to allow access to secrets for PRs created by Dependabot, I thought it could be handled by configuring Dependabot Secrets. And for the dependency-review Job, how about making the specific execution user a condition?

The background is that with pull_request_target, PRs from forked repositories can also access secrets, so I thought it would be better to avoid it if the requirements could be met with the above measures.

Copy link
Contributor

@tasuku43 tasuku43 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!!

@tasuku43 tasuku43 merged commit 4a75844 into main Jan 6, 2026
@tasuku43 tasuku43 deleted the dep-review branch January 6, 2026 06:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants