Skip to content

Avoid sharing npm draft artifacts between workflows #1214

@klutchell

Description

@klutchell

There are various security exploits when downloading artifacts from a previous workflow:

Flowzone only uses this action for one job, npm finalize. If we can finalize in some way that does not require downloading artifacts from a previous run that would be much more secure.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions