Run the static checks (format, lint, typecheck, exception audit, npm registry signatures) and the unit suite with its coverage gate on every pull request and push to main. The workflow is also callable, so the release workflow can require the same gates before building. Every action is pinned to the full commit SHA of its latest release, as the repository now requires. actionlint runs from a checksum-verified release binary and zizmor audits the workflows. Dependabot keeps npm packages and the action pins current, after a 7-day cooldown that zizmor asks for to avoid picking up freshly published malicious versions.
23 lines
438 B
YAML
23 lines
438 B
YAML
version: 2
|
|
updates:
|
|
- package-ecosystem: npm
|
|
directory: /
|
|
schedule:
|
|
interval: weekly
|
|
cooldown:
|
|
default-days: 7
|
|
groups:
|
|
production:
|
|
dependency-type: production
|
|
development:
|
|
dependency-type: development
|
|
- package-ecosystem: github-actions
|
|
directory: /
|
|
schedule:
|
|
interval: weekly
|
|
cooldown:
|
|
default-days: 7
|
|
groups:
|
|
actions:
|
|
patterns: ['*']
|