Skip to content

Npm package updates caught via Dependabot #1

Npm package updates caught via Dependabot

Npm package updates caught via Dependabot #1

Workflow file for this run

# This is a basic workflow to help you get started with Actions
name: npm audit
# Controls when the workflow will run
on:
# Triggers the workflow on push or pull request events but only for the master branch
push:
branches: [ master ]
pull_request:
branches: [ master ]
# Allows you to run this workflow manually from the Actions tab
workflow_dispatch:
# A workflow run is made up of one or more jobs that can run sequentially or in parallel
jobs:
# This workflow contains a single job called "build"
build:
# The type of runner that the job will run on
runs-on: ubuntu-latest
# Steps represent a sequence of tasks that will be executed as part of the job
steps:
# Checks-out your repository under $GITHUB_WORKSPACE, so your job can access it
- uses: actions/checkout@v2
- name: npm-audit
# You may pin to the exact commit or the version.
# uses: luisfontes19/npm-audit-action@447e4d42dd060e6138eccbe55dc43b67f6424100
uses: luisfontes19/[email protected]
with:
# Github Token to create the pull requests
github-token: ${{ secrets.GITHUB_TOKEN }}
# [NPM PARAM] Audit level. Allowed values are: low|moderate|high|critical.
level: low