Skip to content

Document Connect v0.1 supply-chain review#4

Closed
HDauven wants to merge 1 commit into
mainfrom
security/v01-supply-chain-review
Closed

Document Connect v0.1 supply-chain review#4
HDauven wants to merge 1 commit into
mainfrom
security/v01-supply-chain-review

Conversation

@HDauven
Copy link
Copy Markdown
Member

@HDauven HDauven commented May 11, 2026

Summary

  • Adds a targeted v0.1 supply-chain review for Connect.
  • Confirms Connect has no runtime dependencies, no bundled node_modules in dist source maps, clean npm audit output, and expected package contents from npm pack.
  • Records GO for v0.1 dependency posture, with the package version bump left to the final release PR.

Validation

  • npm ci
  • npm run build
  • npm run ci
  • npm pack --dry-run
  • npm pack --dry-run --json
  • npm audit --json
  • Source-map and generated-artifact scans documented in docs/SUPPLY_CHAIN_REVIEW_v0.1.md

No dependencies were upgraded and no generated artifacts/package files are changed.

@HDauven HDauven closed this May 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant