From 3499e96a971632c98aa92f96f760e33d052352aa Mon Sep 17 00:00:00 2001 From: Brice TEXIER Date: Mon, 20 Apr 2026 21:57:59 +0200 Subject: [PATCH] Add yarn_audit_flags option --- README.md | 7 ++++++- action.yml | 4 ++++ script.sh | 2 +- 3 files changed, 11 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index da237a1..b04c65e 100644 --- a/README.md +++ b/README.md @@ -66,6 +66,10 @@ Optional. Do not install yarn. If set to `true`, yarn must be available in the e Optional. The directory from which to look for and run `yarn audit`. Default `.`. +### `yarn_audit_flags` + +Optional. Yarn audit flags. (`yarn audit --json `). + ## Example usage ```yaml @@ -86,6 +90,7 @@ jobs: uses: codeur/action-yarn-audit@v0 with: reporter: github-pr-review + yarn_audit_flags: --level moderate ``` ## Dev @@ -105,7 +110,7 @@ jobs: You can test locally with a command like that: ```sh -GITHUB_WORKSPACE=$(pwd) INPUT_WORKDIR=test/rdjson_formatter/testdata INPUT_TOOL_NAME="yarn audit" INPUT_LEVEL=error INPUT_FAIL_LEVEL=any INPUT_REPORTER=local GITHUB_ACTION_PATH=$(pwd) ./script.sh +GITHUB_WORKSPACE=$(pwd) INPUT_WORKDIR=test/rdjson_formatter/testdata INPUT_TOOL_NAME="yarn audit" INPUT_LEVEL=error INPUT_FAIL_LEVEL=any INPUT_REPORTER=local INPUT_YARN_AUDIT_FLAGS="--level moderate" GITHUB_ACTION_PATH=$(pwd) ./script.sh ``` ## License diff --git a/action.yml b/action.yml index a41d94b..29d9877 100644 --- a/action.yml +++ b/action.yml @@ -37,6 +37,9 @@ inputs: workdir: description: "The directory from which to look for and run yarn audit. Default '.'" default: '.' + yarn_audit_flags: + description: 'Yarn audit flags. (yarn audit --json )' + default: '' runs: using: 'composite' steps: @@ -56,6 +59,7 @@ runs: INPUT_SKIP_INSTALL: ${{ inputs.skip_install }} INPUT_TOOL_NAME: ${{ inputs.tool_name }} INPUT_WORKDIR: ${{ inputs.workdir }} + INPUT_YARN_AUDIT_FLAGS: ${{ inputs.yarn_audit_flags }} branding: icon: 'check-circle' color: 'red' diff --git a/script.sh b/script.sh index 1e1c1dd..16a0bd3 100755 --- a/script.sh +++ b/script.sh @@ -25,7 +25,7 @@ echo "::group:: Running yarn audit with reviewdog 🐶..." # NOTE: yarn audit exits with non-zero code when vulnerabilities are found, # so we suppress its exit code to let reviewdog determine the final result. # shellcheck disable=SC2086 -(yarn audit --json || true) \ +(yarn audit --json ${INPUT_YARN_AUDIT_FLAGS} || true) \ | ruby "${GITHUB_ACTION_PATH}/rdjson_formatter/rdjson_formatter.rb" \ | reviewdog -f=rdjson \ -name="${INPUT_TOOL_NAME}" \