Skip to content

gha: bump anchore/sbom-action from 0.17.3 to 0.17.4 #510

gha: bump anchore/sbom-action from 0.17.3 to 0.17.4

gha: bump anchore/sbom-action from 0.17.3 to 0.17.4 #510

name: 'Dependency Review'
on:
pull_request:
workflow_dispatch:
permissions:
contents: read
jobs:
dependency-review:
runs-on: ubuntu-24.04
steps:
- name: Harden Runner
uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7
with:
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
- name: 'Checkout Repository'
uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871
- name: 'Dependency Review'
uses: actions/dependency-review-action@0659a74c94536054bfa5aeb92241f70d680cc78e