Files
pi-perplexity/.github/workflows/ci.yml
T
Ivan Pereira a24b4e5b05 ci: harden workflows against token exfiltration
Disable checkout credential persistence so repository-controlled code
run by npm ci/test cannot read GITHUB_TOKEN from .git/config, and pin
actions to full commit SHAs to guard against mutable-tag supply-chain
attacks.
2026-07-14 12:42:55 +01:00

31 lines
582 B
YAML

name: CI
on:
push:
branches:
- main
pull_request:
permissions:
contents: read
jobs:
test:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
persist-credentials: false
- name: Setup Node.js
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
with:
node-version: 24
- name: Install dependencies
run: npm ci
- name: Typecheck and test
run: npm run typecheck && npm test