Skip to content

Commit

Permalink
(build) Add yarn npm audit workflows
Browse files Browse the repository at this point in the history
This adds a workflow to run `yarn npm audit` on
every pull request to ensure we do not introduce
security vulnerabilities.
  • Loading branch information
st3phhays committed Apr 30, 2024
1 parent 6d9f752 commit fb32458
Showing 1 changed file with 14 additions and 0 deletions.
14 changes: 14 additions & 0 deletions .github/workflows/audit.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
name: yarn npm audit
on: [pull_request]
jobs:
yarn-npm-audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 20
- run: yarn install --immutable
- name: Run yarn npm audit
run: yarn npm audit --severity moderate
continue-on-error: false

0 comments on commit fb32458

Please sign in to comment.