Skip to content

Commit 84e1892

Browse files
TheStreamCodeclaude
andcommitted
ci: run dependency review on Dependabot pull requests too
The actor filter made this job a no-op. Every dependency change in this repo comes from Dependabot, and because dependency-review is a required status check, a `skipped` run satisfies it -- so the supply-chain gate reported green while reviewing nothing at all. On a public repository the dependency-review API is readable with the Dependabot token, so the job can run for those pull requests. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent 077be62 commit 84e1892

1 file changed

Lines changed: 5 additions & 4 deletions

File tree

‎.github/workflows/dependency-review.yml‎

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -14,10 +14,11 @@ concurrency:
1414
jobs:
1515
dependency-review:
1616
runs-on: ubuntu-latest
17-
# Dependabot PRs run with a restricted token that can't reach the
18-
# dependency-review API, so the check always fails for them. Skip it for
19-
# Dependabot (its bumps are curated) while keeping it for human PRs.
20-
if: ${{ github.actor != 'dependabot[bot]' }}
17+
# No actor filter. Skipping Dependabot made this a no-op: every dependency
18+
# change in this repo comes from Dependabot, and because the job is a required
19+
# status check, a `skipped` run *satisfies* it -- the gate reported green while
20+
# reviewing nothing. On a public repository the dependency-review API is
21+
# readable with the Dependabot token, so the job runs for those PRs too.
2122
steps:
2223
- name: Checkout repository
2324
uses: actions/checkout@v7

0 commit comments

Comments
 (0)