Skip to content

ci: add dependency-review action#1115

Merged
matejchalk merged 1 commit into
mainfrom
dependency-review
Oct 1, 2025
Merged

ci: add dependency-review action#1115
matejchalk merged 1 commit into
mainfrom
dependency-review

Conversation

@matejchalk

@matejchalk matejchalk commented Sep 19, 2025

Copy link
Copy Markdown
Collaborator

Motivation

In light of recent supply chain attack, we decided to enhance our security tooling.

Changes in this PR

Other related changes

@github-actions github-actions Bot added the 🦾 CI/CD Continuous integration and deployment label Sep 19, 2025
@nx-cloud

nx-cloud Bot commented Sep 19, 2025

Copy link
Copy Markdown

View your CI Pipeline Execution ↗ for commit b9984a3

Command Status Duration Result
nx code-pushup --nx-bail -- compare ✅ Succeeded 53s View ↗
nx code-pushup --nx-bail -- ✅ Succeeded 1m 25s View ↗
nx code-pushup --nx-bail -- print-config --outp... ✅ Succeeded 4m 11s View ↗

☁️ Nx Cloud last updated this comment at 2025-09-19 13:22:12 UTC

@nx-cloud

nx-cloud Bot commented Sep 19, 2025

Copy link
Copy Markdown

View your CI Pipeline Execution ↗ for commit b9984a3

Command Status Duration Result
nx code-pushup --nx-bail -- ✅ Succeeded 1m 25s View ↗
nx code-pushup --nx-bail -- print-config --outp... ✅ Succeeded 4m 11s View ↗

☁️ Nx Cloud last updated this comment at 2025-09-19 13:20:33 UTC

@pkg-pr-new

pkg-pr-new Bot commented Sep 19, 2025

Copy link
Copy Markdown

Open in StackBlitz

@code-pushup/ci

npm i https://pkg.pr.new/code-pushup/cli/@code-pushup/ci@1115

@code-pushup/cli

npm i https://pkg.pr.new/code-pushup/cli/@code-pushup/cli@1115

@code-pushup/core

npm i https://pkg.pr.new/code-pushup/cli/@code-pushup/core@1115

@code-pushup/create-cli

npm i https://pkg.pr.new/code-pushup/cli/@code-pushup/create-cli@1115

@code-pushup/nx-plugin

npm i https://pkg.pr.new/code-pushup/cli/@code-pushup/nx-plugin@1115

@code-pushup/models

npm i https://pkg.pr.new/code-pushup/cli/@code-pushup/models@1115

@code-pushup/coverage-plugin

npm i https://pkg.pr.new/code-pushup/cli/@code-pushup/coverage-plugin@1115

@code-pushup/eslint-plugin

npm i https://pkg.pr.new/code-pushup/cli/@code-pushup/eslint-plugin@1115

@code-pushup/js-packages-plugin

npm i https://pkg.pr.new/code-pushup/cli/@code-pushup/js-packages-plugin@1115

@code-pushup/jsdocs-plugin

npm i https://pkg.pr.new/code-pushup/cli/@code-pushup/jsdocs-plugin@1115

@code-pushup/lighthouse-plugin

npm i https://pkg.pr.new/code-pushup/cli/@code-pushup/lighthouse-plugin@1115

@code-pushup/typescript-plugin

npm i https://pkg.pr.new/code-pushup/cli/@code-pushup/typescript-plugin@1115

@code-pushup/utils

npm i https://pkg.pr.new/code-pushup/cli/@code-pushup/utils@1115

@code-pushup/models-transformers

npm i https://pkg.pr.new/code-pushup/cli/@code-pushup/models-transformers@1115

commit: b9984a3

@github-actions

Copy link
Copy Markdown
Contributor

Code PushUp

🤨 Code PushUp report has both improvements and regressions – compared current commit f012142 with previous commit 3b5db5b.

🕵️ See full comparison in Code PushUp portal 🔍

🏷️ Categories

🏷️ Category ⭐ Previous score ⭐ Current score 🔄 Score change
Performance 🔴 35 🔴 41 ↑ +5.8
Documentation 🔴 25 🔴 24 ↓ −0.2
Code coverage 🟡 90 🟡 90 ↑ +0.1
Security 🟡 56 🟡 56
Updates 🟡 85 🟡 85
Accessibility 🟢 92 🟢 92
Best Practices 🟢 100 🟢 100
SEO 🟡 61 🟡 61
Type Safety 🟢 100 🟢 100
Bug prevention 🟢 100 🟢 100
Miscellaneous 🟢 100 🟢 100
Code style 🟢 100 🟢 100
👍 2 groups improved, 👎 1 group regressed, 👍 6 audits improved, 👎 5 audits regressed, 11 audits changed without impacting score

🗃️ Groups

🔌 Plugin 🗃️ Group ⭐ Previous score ⭐ Current score 🔄 Score change
Lighthouse Performance 🔴 35 🔴 41 ↑ +5.8
JSDoc coverage Documentation coverage 🔴 25 🔴 24 ↓ −0.2
Code coverage Code coverage metrics 🟡 90 🟡 90 ↑ +0.1

18 other groups are unchanged.

🛡️ Audits

🔌 Plugin 🛡️ Audit 📏 Previous value 📏 Current value 🔄 Value change
Lighthouse Initial server response time was short 🟩 Root document took 590 ms 🟥 Root document took 630 ms ↑ +8.2 %
Lighthouse Avoids enormous network payloads 🟨 Total size was 2,676 KiB 🟩 Total size was 2,036 KiB ↓ −23.9 %
Lighthouse Total Blocking Time 🟥 2,840 ms 🟥 1,100 ms ↓ −61.3 %
Lighthouse Time to Interactive 🟥 16.8 s 🟥 12.7 s ↓ −24.3 %
Lighthouse Speed Index 🟥 6.3 s 🟥 6.3 s ↑ +1.1 %
Lighthouse First Contentful Paint 🟨 3.0 s 🟥 3.0 s ↑ +1.3 %
Lighthouse Max Potential First Input Delay 🟥 1,080 ms 🟥 720 ms ↓ −32.8 %
JSDoc coverage Functions coverage 🟥 521 undocumented functions 🟥 521 undocumented functions  +0 %
Code coverage Function coverage 🟩 92.1 % 🟩 92.3 % ↑ +0.2 %
JSDoc coverage Types coverage 🟥 243 undocumented types 🟥 241 undocumented types ↓ −0.8 %
Code coverage Branch coverage 🟨 85.6 % 🟨 85.5 % ↓ −0.1 %
Lighthouse Metrics 🟩 100% 🟩 100% ↓ −24.3 %
Lighthouse Minimizes main-thread work 🟥 11.2 s 🟥 9.2 s ↓ −18.2 %
Lighthouse JavaScript execution time 🟥 5.2 s 🟥 3.6 s ↓ −31.4 %
Lighthouse Uses efficient cache policy on static assets 🟨 30 resources found 🟨 31 resources found ↑ +0.2 %
Lighthouse Server Backend Latencies 🟩 970 ms 🟩 1,650 ms ↑ +71.1 %
Lighthouse Largest Contentful Paint 🟥 10.9 s 🟥 11.4 s ↑ +4.4 %
Lighthouse Reduce unused CSS 🟥 Potential savings of 113 KiB 🟥 Potential savings of 102 KiB ↓ −50.8 %
Lighthouse Reduce unused JavaScript 🟥 Potential savings of 602 KiB 🟥 Potential savings of 155 KiB ↓ −17.6 %
Lighthouse Network Round Trip Times 🟩 10 ms 🟩 70 ms ↑ +568 %
Lighthouse Avoids an excessive DOM size 🟥 2,288 elements 🟥 2,306 elements ↑ +0.8 %
Code coverage Line coverage 🟨 86.3 % 🟨 86.3 % ↑ +0.1 %

588 other audits are unchanged.

@matejchalk matejchalk marked this pull request as ready for review September 19, 2025 14:45
@matejchalk matejchalk requested review from hanna-skryl and vmasek and removed request for vmasek October 1, 2025 08:01
@matejchalk matejchalk merged commit 33714e2 into main Oct 1, 2025
23 checks passed
@matejchalk matejchalk deleted the dependency-review branch October 1, 2025 14:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🦾 CI/CD Continuous integration and deployment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants