Skip to content

Conversation

dominikg
Copy link
Member

  • --prefer-offline isn't needed
  • pinning changesets/action prevents malicious updates creeping in
  • remove .npmrc after use to avoid it leaking token

Copy link
Member

@pngwn pngwn left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks great! Nice catch about the npmrc.

@dominikg dominikg merged commit 54fa669 into main Aug 22, 2024
6 checks passed
@dominikg dominikg deleted the chore/harden-actions branch August 22, 2024 09:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants