Skip to content

Commit 33a653c

Browse files
committed
security: stricter pnpm config blockExoticSubdeps & trustPolicy
1 parent b9feeb6 commit 33a653c

2 files changed

Lines changed: 2 additions & 12 deletions

File tree

.github/workflows/pr.yml

Lines changed: 0 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -47,18 +47,6 @@ jobs:
4747
run: pnpm run build:all
4848
- name: Publish Previews
4949
run: pnpx pkg-pr-new publish --pnpm --compact './packages/*' --template './examples/*/*'
50-
provenance:
51-
name: Provenance
52-
runs-on: ubuntu-latest
53-
steps:
54-
- name: Checkout
55-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
56-
with:
57-
persist-credentials: false
58-
- name: Check Provenance
59-
uses: danielroe/provenance-action@41bcc969e579d9e29af08ba44fcbfdf95cee6e6c # v0.1.1
60-
with:
61-
fail-on-downgrade: true
6250
version-preview:
6351
name: Version Preview
6452
runs-on: ubuntu-latest

pnpm-workspace.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,8 @@
11
cleanupUnusedCatalogs: true
22
linkWorkspacePackages: true
33
preferWorkspacePackages: true
4+
blockExoticSubdeps: true
5+
trustPolicy: 'no-downgrade'
46

57
packages:
68
- 'packages/*'

0 commit comments

Comments
 (0)