-
Notifications
You must be signed in to change notification settings - Fork 8
Expand file tree
/
Copy pathanalyze-dependabot-reusable.yaml
More file actions
57 lines (48 loc) · 2.11 KB
/
analyze-dependabot-reusable.yaml
File metadata and controls
57 lines (48 loc) · 2.11 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
#
# Licensed to the Apache Software Foundation (ASF) under one or more
# contributor license agreements. See the NOTICE file distributed with
# this work for additional information regarding copyright ownership.
# The ASF licenses this file to you under the Apache License, Version 2.0
# (the "License"); you may not use this file except in compliance with
# the License. You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
name: Dependabot Analyze PR
on:
workflow_call: { }
# Explicitly drop all permissions inherited from the caller for security.
# Reference: https://docs.github.com/en/actions/sharing-automations/reusing-workflows#access-and-permissions
permissions: { }
jobs:
analyze-pull-request:
# Skip this workflow on commits not pushed by Dependabot
if: ${{ github.actor == 'dependabot[bot]' }}
runs-on: ubuntu-latest
steps:
- name: Fetch Dependabot metadata
id: dependabot
uses: dependabot/fetch-metadata@08eff52bf64351f401fb50d4972fa95b9f2c2d1b # 2.4.0
with:
github-token: ${{ github.token }}
# Creates the data required by the `process-dependabot-reusable` workflow as JSON files.
- name: Create artifacts
shell: bash
env:
PULL_REQUEST: ${{ toJSON(github.event.pull_request) }}
UPDATED_DEPENDENCIES: ${{ steps.dependabot.outputs.updated-dependencies-json }}
run: |
mkdir dependabot-metadata
echo "$PULL_REQUEST" > dependabot-metadata/pull_request.json
echo "$UPDATED_DEPENDENCIES" > dependabot-metadata/updated_dependencies.json
- name: Upload artifacts
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # 4.6.2
with:
name: dependabot-metadata
path: dependabot-metadata