Skip to content

Add Bomly Guard workflow - #1

Merged
bomly-guy merged 6 commits into
mainfrom
codex/add-bomly-guard
Jun 19, 2026
Merged

Add Bomly Guard workflow#1
bomly-guy merged 6 commits into
mainfrom
codex/add-bomly-guard

Conversation

@bomly-guy

@bomly-guy bomly-guy commented Jun 12, 2026

Copy link
Copy Markdown
Member

Summary

  • Adds the Bomly Guard dogfooding workflow and README examples for tag-based dependency diffs
  • Clarifies workflow-owned package-manager setup before Bomly Guard runs
  • Keeps Bomly Guard pointed at bomly-dev/bomly-guard@v1

Validation

  • npm test, npm run lint:shell, and npm run lint:js passed in bomly-guard
  • Parsed all Bomly Guard workflow YAML files across examples
  • Ran git diff --check in bomly-guard and all example repos
  • Spot-checked bomly diff for pnpm, Go, and Dart tag comparisons

@github-actions

github-actions Bot commented Jun 12, 2026

Copy link
Copy Markdown

Bomly Diff Summary

Compared 559a762aeef68b0e5c818f62dfba67abc369912f to 4b29d91896155be303d5a6be70d80c8733196281.

Overview

Status Manifests Dependencies Findings Duration
❌ Failing findings introduced +0 / ~1 / -0 +0 / ~1 / -0 1 introduced / 0 persisted / 1 resolved 44985ms

Dependency Changes

Summary: 0 added, 1 changed, 0 removed.

Changed Dependencies

Change Package Version Scope Licenses PURL
changed minimist 0.0.10 → 0.0.8 runtime MIT pkg:npm/minimist@0.0.8

Vulnerabilities

✅ No vulnerability changes.

License Changes

✅ No license changes.

Project Posture

✅ No project posture changes (or --matchers +scorecard was not selected).

Policy Findings

Summary: 1 introduced, 0 persisted, 1 resolved.

Introduced Findings

Status Category Severity Disposition ID Package Fixed In Exploitability Title
introduced vulnerability CRITICAL fail GHSA-xvch-5gv4-984h minimist@0.0.8 0.2.4 risk 4.3 Prototype Pollution in minimist

Resolved Findings

Status Category Severity Disposition ID Package Fixed In Exploitability Title
resolved vulnerability CRITICAL fail GHSA-xvch-5gv4-984h minimist@0.0.10 0.2.4 risk 4.3 Prototype Pollution in minimist

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@bomly-guy
bomly-guy marked this pull request as ready for review June 13, 2026 07:01
@bomly-guy
bomly-guy merged commit c226b2c into main Jun 19, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants