dependency-review-action
dependency-review-action copied to clipboard
Show vulnerabities and license information on the job summary.
Users can see the results that were found directly on the job summary
All the results are grouped by manifest.
It shows a table with vulnerable packages, together with package version, the vulnerabily info and it's severity.
Shows info about package licenses, which packages have a non allowed license, and the list of packages with unknown licenses.
@tspascoal ~Thanks! Do you mind adding a screenshot of how this would look like, or linking to an Action run we can use to see the behavior before merging?~
Please ignore, found after I clicked the diff!