Skip to content

Add CI to enforce pnpm usage#430

Merged
Olmo Maldonado (ibolmo) merged 1 commit intomainfrom
sec-disallow-npm
Apr 2, 2026
Merged

Add CI to enforce pnpm usage#430
Olmo Maldonado (ibolmo) merged 1 commit intomainfrom
sec-disallow-npm

Conversation

@ibolmo
Copy link
Copy Markdown
Collaborator

This commit introduces a GitHub Actions workflow to reject pull requests that include package-lock.json. It also updates .npmrc to enable engine strictness and modifies package.json to include a preinstall script and engine specifications that prompt users to use pnpm.

This commit introduces a GitHub Actions workflow to reject pull requests
that include `package-lock.json`. It also updates `.npmrc` to enable
engine strictness and modifies `package.json` to include a `preinstall`
script and engine specifications that prompt users to use pnpm.
@vercel
Copy link
Copy Markdown

vercel bot commented Apr 1, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
ai-proxy Ready Ready Preview, Comment Apr 1, 2026 1:40am

Request Review

@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedjsonwebtoken@​9.0.29910010085100
Addeditty-router@​3.0.121001009989100
Addedjose@​5.9.610010010091100

View full report

@ibolmo Olmo Maldonado (ibolmo) merged commit 8e37c95 into main Apr 2, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants