Skip to content

Commit 8737cb2

Browse files
committed
security: stricter pnpm config blockExoticSubdeps & trustPolicy
1 parent 58d0232 commit 8737cb2

2 files changed

Lines changed: 2 additions & 12 deletions

File tree

.github/workflows/pr.yml

Lines changed: 0 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -48,18 +48,6 @@ jobs:
4848
run: pnpm run build:all
4949
- name: Publish Previews
5050
run: pnpx pkg-pr-new@0.0.71 publish --pnpm './packages/*' --template './examples/*/*'
51-
provenance:
52-
name: Provenance
53-
runs-on: ubuntu-latest
54-
steps:
55-
- name: Checkout
56-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
57-
with:
58-
persist-credentials: false
59-
- name: Check Provenance
60-
uses: danielroe/provenance-action@41bcc969e579d9e29af08ba44fcbfdf95cee6e6c # v0.1.1
61-
with:
62-
fail-on-downgrade: true
6351
version-preview:
6452
name: Version Preview
6553
runs-on: ubuntu-latest

pnpm-workspace.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,8 @@
11
cleanupUnusedCatalogs: true
22
linkWorkspacePackages: true
33
preferWorkspacePackages: true
4+
blockExoticSubdeps: true
5+
trustPolicy: 'no-downgrade'
46

57
packages:
68
- examples/**/*

0 commit comments

Comments
 (0)