Skip to content

Commit cb5fbc5

Browse files
committed
chore: supply-chain hardening — lockfile enforcement + action SHA pins
1 parent 1cff9e8 commit cb5fbc5

2 files changed

Lines changed: 11 additions & 10 deletions

File tree

.github/workflows/ci.yml

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -11,19 +11,19 @@ jobs:
1111
runs-on: ubuntu-latest
1212
steps:
1313
- name: Checkout repo
14-
uses: actions/checkout@v4
14+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
1515
- name: Set up node
16-
uses: actions/setup-node@v4
16+
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
1717
- name: Compile
1818
run: yarn && yarn build
1919

2020
test:
2121
runs-on: ubuntu-latest
2222
steps:
2323
- name: Checkout repo
24-
uses: actions/checkout@v4
24+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
2525
- name: Set up node
26-
uses: actions/setup-node@v4
26+
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
2727
- name: Compile & Test
2828
run: yarn && yarn test
2929

@@ -32,11 +32,11 @@ jobs:
3232
runs-on: ubuntu-latest
3333
steps:
3434
- name: Checkout repo
35-
uses: actions/checkout@v4
35+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
3636
- name: Set up node
37-
uses: actions/setup-node@v4
37+
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
3838
with:
39-
node-version: 21
39+
node-version: 22
4040
- name: Build
4141
run: yarn && yarn build
4242
- name: test examples
@@ -57,11 +57,11 @@ jobs:
5757
runs-on: ubuntu-latest
5858
steps:
5959
- name: Checkout repo
60-
uses: actions/checkout@v4
60+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
6161
- name: Set up node
62-
uses: actions/setup-node@v4
62+
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
6363
- name: Install dependencies
64-
run: yarn install
64+
run: yarn install --immutable
6565
- name: Build
6666
run: yarn build
6767
- name: Publish to npm

.yarnrc.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
npmMinimalAgeGate: 10080

0 commit comments

Comments
 (0)