Skip to content

docs: Update RELEASE.md to include explicit cargo-semver-checks install #847

docs: Update RELEASE.md to include explicit cargo-semver-checks install

docs: Update RELEASE.md to include explicit cargo-semver-checks install #847

name: Dependency Review
on:
push:
pull_request:
merge_group:
jobs:
dependency-review:
name: Github Dependency Review
runs-on: ubuntu-latest
permissions:
pull-requests: write
contents: read
steps:
- name: Checkout Repository
uses: actions/checkout@v4
- name: Dependency Review
uses: actions/dependency-review-action@v4
with:
allow-licenses: >-
MIT,
Apache-2.0,
BSD-3-Clause,
ISC,
Unicode-DFS-2016
# [email protected] is licensed as (MIT OR Apache-2.0), but the Github api fails to detect it: https://github.com/rust-cli/anstyle/tree/main/crates/anstyle
# AND combinations are currently bugged (https://github.com/actions/dependency-review-action/issues/263):
# * [email protected] License: Apache-2.0 AND MIT
# * [email protected] License: (MIT OR Apache-2.0) AND Unicode-DFS-2016
allow-dependencies-licenses: 'pkg:cargo/[email protected], pkg:cargo/[email protected], pkg:cargo/[email protected]'
comment-summary-in-pr: on-failure
# Explicit refs required for merge_group and push triggers:
# https://github.com/actions/dependency-review-action/issues/456
# https://github.com/actions/dependency-review-action/issues/252
base-ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.base.sha || (github.event_name == 'push' && github.event.before || (github.event_name == 'merge_group' && 'main' || 'unsupported trigger' ) ) }}
head-ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.sha || (github.event_name == 'push' && github.sha || (github.event_name == 'merge_group' && github.ref || 'unsupported trigger' ) ) }}