Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add GHA to submit dependencies to dependabot #5440

Merged
merged 2 commits into from
Oct 30, 2024

Conversation

arnaualcazar
Copy link
Collaborator

@arnaualcazar arnaualcazar commented Oct 28, 2024

Added a Github action to generate and submit the dependencies used by the project. Then, dependabot will be able to display the vulnerabilities found on the libraries used by Nextflow.

Task has been tested on PR:
image

although result cannot be published because it is not being run from master branch:

Notice: Submitted dependency-graph-reports/generate_and_submit_dependency_graph_for_nextflow-dependency-submission-nextflow.json: The snapshot was accepted, but it is not for the default branch. It will not update dependency results for the repository.

Signed-off-by: Arnau Alcázar Lleopart <[email protected]>
@arnaualcazar arnaualcazar self-assigned this Oct 28, 2024
Copy link

netlify bot commented Oct 28, 2024

Deploy Preview for nextflow-docs-staging canceled.

Name Link
🔨 Latest commit 6a9c00c
🔍 Latest deploy log https://app.netlify.com/sites/nextflow-docs-staging/deploys/671fbf4018d54c0008d67e4e

Signed-off-by: Arnau Alcázar Lleopart <[email protected]>
@arnaualcazar arnaualcazar marked this pull request as ready for review October 28, 2024 16:54
@pditommaso pditommaso merged commit 80395a6 into master Oct 30, 2024
22 checks passed
@pditommaso pditommaso deleted the add-gha-submit-dependecies branch October 30, 2024 07:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants