Skip to content

chore: apply security best practices and onboard stepsecurity #177

chore: apply security best practices and onboard stepsecurity

chore: apply security best practices and onboard stepsecurity #177

Workflow file for this run

name: Commit Lint
on:
pull_request:
branches: [master]
permissions:
contents: read
jobs:
commit_lint:
name: "Lint commit messages"
runs-on: ubuntu-latest
permissions:
id-token: write
steps:
- name: Harden the runner
uses: step-security/harden-runner@95d9a5deda9de15063e7595e9719c11c38c90ae2 # v2.13.2
with:
egress-policy: block
policy: global-allowed-endpoints-policy
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
with:
fetch-depth: 0
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: 16
- run: yarn install --frozen-lockfile
- run: npx commitlint --from ${{ github.event.pull_request.base.sha }} --to ${{ github.event.pull_request.head.sha }} --verbose