diff --git a/.github/workflows/dependency-submission.yml b/.github/workflows/dependency-submission.yml deleted file mode 100644 index 60fbdf4..0000000 --- a/.github/workflows/dependency-submission.yml +++ /dev/null @@ -1,42 +0,0 @@ -name: Dependency submission - -# Populates GitHub's dependency graph for this repo. NuGet manifests are not parsed automatically -# when versions come from Directory.Packages.props or transitive restore, so without this the graph -# is empty: Dependabot has less to work with, the Insights > Dependencies tab is blank, and this -# repo never shows up in the "Used by"/dependents view of the packages it consumes. -on: - push: - branches: [master] - schedule: - # Weekly, so the graph does not drift when a dependency changes without a push. - - cron: "17 5 * * 1" - workflow_dispatch: - -permissions: - contents: write - -jobs: - submit: - name: Submit dependency graph - runs-on: ubuntu-latest - steps: - - name: Checkout code - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - - - name: Setup .NET SDK - uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6 - with: - dotnet-version: | - 10.0.x - 11.0.x - - - name: Restore - # component-detection reads obj/project.assets.json; on a bare checkout it finds nothing and - # submits an empty snapshot. Restore is what turns PackageReference into resolved versions - # and transitive dependencies, which is the whole reason to submit a graph by hand. - run: dotnet restore - - - name: Detect and submit dependencies - uses: advanced-security/component-detection-dependency-submission-action@b282c67b1008fde9b60da4bdfcd8849613e293b2 # v0.1.6 - with: - filePath: .