-
Notifications
You must be signed in to change notification settings - Fork 19
NPM workflow: Used trusted publishing #2700
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Files
|
|
|
||
| - name: Run npm-prepare-release | ||
| uses: Automattic/vip-actions/npm-prepare-release@1137b91acf0f5ea4e0db044bcf14ceabed9b068f # trunk | ||
| uses: Automattic/vip-actions/npm-prepare-release@v0.7.3 |
Check warning
Code scanning / CodeQL
Unpinned tag for a non-immutable Action in workflow Medium
Uses Step
| pull-requests: write | ||
| steps: | ||
| - uses: Automattic/vip-actions/npm-publish-prerelease@1137b91acf0f5ea4e0db044bcf14ceabed9b068f # trunk | ||
| - uses: Automattic/vip-actions/npm-publish@v0.7.3 |
Check warning
Code scanning / CodeQL
Unpinned tag for a non-immutable Action in workflow Medium
Uses Step
| pull-requests: write | ||
| steps: | ||
| - uses: Automattic/vip-actions/npm-publish@1137b91acf0f5ea4e0db044bcf14ceabed9b068f # trunk | ||
| - uses: Automattic/vip-actions/npm-publish@v0.7.3 |
Check warning
Code scanning / CodeQL
Unpinned tag for a non-immutable Action in workflow Medium
Uses Step
783d863 to
6805de2
Compare
6805de2 to
50ddaa8
Compare
|



No description provided.