Skip to content

ci: add weekly dependency audit workflow#1021

Open
liujuanjuan1984 wants to merge 2 commits intoa2aproject:mainfrom
liujuanjuan1984:chore/weekly-dependency-audit
Open

ci: add weekly dependency audit workflow#1021
liujuanjuan1984 wants to merge 2 commits intoa2aproject:mainfrom
liujuanjuan1984:chore/weekly-dependency-audit

Conversation

@liujuanjuan1984
Copy link
Copy Markdown
Contributor

Summary

  • add a weekly dependency audit workflow with manual dispatch and PR triggers for dependency changes
  • fail the workflow on runtime dependency vulnerabilities
  • surface development dependency vulnerabilities as warnings without blocking merges
  • export non-editable, unhashed requirements for pip-audit compatibility with uv

Why

Dependabot version updates are already configured, but uv does not currently support Dependabot security updates. This adds lightweight dependency vulnerability coverage without turning dev-only findings into merge blockers.

@liujuanjuan1984 liujuanjuan1984 requested a review from a team as a code owner April 27, 2026 11:20
@gemini-code-assist
Copy link
Copy Markdown
Contributor

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant