dependency-review-action icon indicating copy to clipboard operation
dependency-review-action copied to clipboard

Show vulnerabities and license information on the job summary.

Open tspascoal opened this issue 2 years ago • 1 comments

Users can see the results that were found directly on the job summary

All the results are grouped by manifest.

It shows a table with vulnerable packages, together with package version, the vulnerabily info and it's severity.

Shows info about package licenses, which packages have a non allowed license, and the list of packages with unknown licenses.

tspascoal avatar Aug 04 '22 15:08 tspascoal

@tspascoal ~Thanks! Do you mind adding a screenshot of how this would look like, or linking to an Action run we can use to see the behavior before merging?~

Please ignore, found after I clicked the diff!

febuiles avatar Aug 05 '22 21:08 febuiles