security: stricter pnpm config blockExoticSubdeps & trustPolicy#2186
security: stricter pnpm config blockExoticSubdeps & trustPolicy#2186Sheraff wants to merge 1 commit into
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
💤 Files with no reviewable changes (1)
📝 WalkthroughWalkthroughThis PR updates two independent infrastructure components: it replaces the provenance verification job with a new version preview job in the GitHub Actions workflow, and it adds two pnpm workspace configuration options to enforce dependency security policies. ChangesCI Workflow Update
pnpm Workspace Configuration
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
View your CI Pipeline Execution ↗ for commit 5f41ed7
☁️ Nx Cloud last updated this comment at |
Summary
Validation
Summary by CodeRabbit