Skip to content

Write dependency change guardrail #20

@jdelfino

Description

@jdelfino

Write the dependency change detection guardrail check.

File

.github/workflows/guardrail-dependencies.yml

What

  • Trigger: PR opened or synchronized
  • Detect changes to: package.json, requirements.txt, go.mod, Cargo.toml, pom.xml, etc.
  • If new dependencies added: check PR body and linked issue for justification
  • No justification: action_required with annotation on dependency file
  • Check for non-stale PR approval override

Reference

  • docs/design.md: Dependency Change Detection (Layer 4)

Metadata

Metadata

Assignees

No one assigned

    Labels

    taskImplementation work item

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions