Skip to content

docs: add scoped PTP timing and failure-handling contract #37

docs: add scoped PTP timing and failure-handling contract

docs: add scoped PTP timing and failure-handling contract #37

name: Dependency Review
on:
pull_request:
branches: [ main, master ]
permissions:
contents: read
pull-requests: write
jobs:
dependency-review:
name: Dependency Review
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Checkout
uses: actions/checkout@v7
# Preferred gate: evaluates dependency changes against GitHub's dependency graph.
# Some repositories can have the graph unavailable/disabled. Treat that as a
# capability failure, not as permission to skip dependency security validation.
- name: GitHub dependency review
id: github_dependency_review
continue-on-error: true
uses: actions/dependency-review-action@v4
with:
config-file: .github/dependency-review-config.yml
- name: Setup .NET fallback
if: steps.github_dependency_review.outcome == 'failure'
uses: actions/setup-dotnet@v6
with:
dotnet-version: '8.0.x'
- name: NuGet vulnerability audit fallback
if: steps.github_dependency_review.outcome == 'failure'
shell: bash
run: |
set -euo pipefail
echo "GitHub dependency review is unavailable or failed; enforcing NuGet audit fallback."
audit_log="$RUNNER_TEMP/nuget-audit.log"
set +e
dotnet restore ./PtpLabClock.sln \
-p:EnableWindowsTargeting=true \
-p:NuGetAudit=true \
-p:NuGetAuditMode=all 2>&1 | tee "$audit_log"
restore_exit=${PIPESTATUS[0]}
set -e
if [[ "$restore_exit" -ne 0 ]]; then
echo "NuGet restore/audit failed with exit code $restore_exit." >&2
exit "$restore_exit"
fi
if grep -Eq 'warning NU190[1-4]:' "$audit_log"; then
echo "NuGet audit found a package vulnerability (NU1901-NU1904)." >&2
grep -E 'warning NU190[1-4]:' "$audit_log" >&2 || true
exit 1
fi
echo "NuGet audit completed without NU1901-NU1904 vulnerability warnings."