diff --git a/README.md b/README.md index 48ea01e..7b90546 100644 --- a/README.md +++ b/README.md @@ -1,7 +1,8 @@ # dependency-review-action -This Action scans your pull requests for vulnerabilities introduced -when modifying your project's dependencies. A check in your pull requests will notify you of the results. +This action scans your pull requests for dependency changes and will raise an error if any new dependencies have existing vulnerabilities. The action is supported by an [API endpoint](https://docs.github.com/en/rest/reference/dependency-graph#dependency-review) that diffs the dependencies between any two revisions. + +The action is available for all public repositories, as well as private repositories that have Github Advanced Security licensed. Screen Shot 2022-03-31 at 1 10 51 PM diff --git a/action.yml b/action.yml index 68c748a..631d257 100644 --- a/action.yml +++ b/action.yml @@ -1,5 +1,5 @@ name: 'Dependency Review' -description: 'GitHub Action for Dependency Review' +description: 'Prevent the introduction of dependencies with known vulnerabilities' author: 'GitHub' inputs: repo-token: