Files
xread/.github/workflows/security-governance.yml
T
dependabot[bot] 9185106fde chore(deps): bump actions/setup-node in the github-actions group
Bumps the github-actions group with 1 update: [actions/setup-node](https://github.com/actions/setup-node).


Updates `actions/setup-node` from 6 to 7
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](https://github.com/actions/setup-node/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-20 01:35:16 +00:00

46 lines
914 B
YAML

name: Security Governance
on:
pull_request:
push:
branches:
- main
schedule:
- cron: "31 17 * * 1"
workflow_dispatch:
permissions:
contents: read
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
jobs:
npm-audit-policy:
name: Enforce npm audit policy
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- name: Check out repository
uses: actions/checkout@v7
- name: Set up Node.js
uses: actions/setup-node@v7
with:
node-version: 26
cache: npm
- name: Install dependencies
run: npm ci
- name: Enforce dependency security policy
run: npm run security:audit
- name: Upload security audit artifacts
if: always()
uses: actions/upload-artifact@v7
with:
name: security-audit-report
path: security-reports/
if-no-files-found: error