We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 1d5cd0f commit 06eb0e9Copy full SHA for 06eb0e9
.github/workflows/cd.yml
@@ -10,6 +10,12 @@ jobs:
10
build:
11
runs-on: ubuntu-latest
12
13
+ permissions:
14
+ contents: write
15
+ issues: write
16
+ pull-requests: write
17
+ id-token: write
18
+
19
steps:
20
- name: Check out branch
21
uses: actions/checkout@v4
@@ -24,6 +30,9 @@ jobs:
24
30
- name: Install modules
25
31
run: npm ci --no-audit --ignore-scripts
26
32
33
+ - name: Verify the integrity of installed dependencies
34
+ run: npm audit signatures
35
27
36
- name: Lint
28
37
run: npm run lint
29
38
.github/workflows/ci.yml
@@ -9,6 +9,10 @@ on:
9
jobs:
+ contents: read
- name: Check out repository
0 commit comments