Skip to content

SCANNPM-122 Avoid usage of "npm install" and use fix versions#353

Merged
vdiez merged 3 commits intomasterfrom
npm-install
Dec 1, 2025
Merged

SCANNPM-122 Avoid usage of "npm install" and use fix versions#353
vdiez merged 3 commits intomasterfrom
npm-install

Conversation

@vdiez
Copy link
Contributor

@vdiez vdiez commented Dec 1, 2025

No description provided.

@vdiez vdiez requested a review from jdkandersson December 1, 2025 12:58
@hashicorp-vault-sonar-prod hashicorp-vault-sonar-prod bot changed the title Avoid usage of "npm install" and use fix versions SCANNPM-122 Avoid usage of "npm install" and use fix versions Dec 1, 2025
@hashicorp-vault-sonar-prod
Copy link

hashicorp-vault-sonar-prod bot commented Dec 1, 2025

SCANNPM-122

@vdiez vdiez requested a review from jdkandersson December 1, 2025 13:59
@sonarqubecloud
Copy link

sonarqubecloud bot commented Dec 1, 2025

SonarQube reviewer guide

Summary: Consolidate Knip validation into main build step and add private npm registry configuration for integration tests.

Review Focus: The addition of private Artifactory registry authentication and its usage during integration tests. Verify the secret retrieval and npm config steps properly secure credentials. The removal of the standalone Knip job should be validated against CI/CD requirements.

Start review at: .github/workflows/build.yml. This is the critical file as it changes authentication flow, adds registry configuration, and modifies the CI pipeline structure by consolidating Knip execution.

💬 Please send your feedback

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

@vdiez vdiez enabled auto-merge (squash) December 1, 2025 14:07
@vdiez vdiez merged commit 791b6bb into master Dec 1, 2025
7 checks passed
@vdiez vdiez deleted the npm-install branch December 1, 2025 14:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants