Skip to content

lvm: lvm_pv on RHEL 8, role fixes, Molecule scenario and Python 3.6 unit tests #253

lvm: lvm_pv on RHEL 8, role fixes, Molecule scenario and Python 3.6 unit tests

lvm: lvm_pv on RHEL 8, role fixes, Molecule scenario and Python 3.6 unit tests #253

name: 'Dependency Review'
on:
pull_request: {}
permissions:
contents: 'read'
jobs:
dependency-review:
runs-on: 'ubuntu-latest'
steps:
- name: 'Harden Runner'
uses: 'step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1' # v2.21.1
with:
egress-policy: 'audit'
- name: 'Checkout repository'
uses: 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' # v7.0.1
- name: 'Dependency Review'
uses: 'actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294' # v5.0.0
with:
# GHSA-6w46-j5rx-g56g against pytest 6.2.5 in .github/unit-tests-py36. The only fixed
# release is 9.0.3, which requires Python 3.10, while that lockfile feeds the unit tests
# on the Python 3.6 of RHEL 8, where the test runner has to run on the same interpreter
# as the modules under test. The advisory covers other local users abusing the
# predictable /tmp/pytest-of-{user} directories; the tests run in a throwaway UBI 8
# container without other users. Drop this entry once the py36 lockfile is retired
# together with RHEL 8 support.
allow-ghsas: 'GHSA-6w46-j5rx-g56g'