Skip to content

Bump actions/checkout from 5.0.0 to 6.0.1 #1416

Bump actions/checkout from 5.0.0 to 6.0.1

Bump actions/checkout from 5.0.0 to 6.0.1 #1416

name: Dependency review
on: [pull_request]
permissions: read-all
jobs:
dependency-review:
name: Dependency review
runs-on: ubuntu-latest
steps:
- uses: step-security/harden-runner@95d9a5deda9de15063e7595e9719c11c38c90ae2
with:
disable-sudo: true
egress-policy: block
allowed-endpoints: >
api.github.com:443
api.securityscorecards.dev:443
github.com:443
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8
- uses: actions/dependency-review-action@3c4e3dcb1aa7874d2c16be7d79418e9b7efd6261
with:
allow-ghsas: GHSA-pq67-6m6q-mj2v # urllib3