Skip to content

Conversation

asturur
Copy link
Member

@asturur asturur commented Sep 21, 2025

Description

Improve the security of the changelog action by:

  • extract artifacts in an empty isolated folder
  • avoid use templates in scripts when we can use process.ENV from node
  • avoid npm ci on pr branches
  • checkout only needed files for changelog update

Copy link

codesandbox bot commented Sep 21, 2025

Review or Edit in CodeSandbox

Open the branch in Web EditorVS CodeInsiders

Open Preview

Copy link
Contributor

Build Stats

file / KB (diff) bundled minified
fabric 916.352 (0) 301.665 (0)

@asturur asturur merged commit b30cad6 into master Sep 21, 2025
15 of 16 checks passed
@asturur asturur deleted the changelog-action branch September 21, 2025 07:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant