Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add 'npm audit signatures' to CI workflow. #925

Merged
merged 2 commits into from
Nov 18, 2024

Conversation

sanason
Copy link
Member

@sanason sanason commented Nov 14, 2024

This PR is related to the Trello card Implement subresource integrity for all analytics.usa.gov application components. npm audit signatures "verifies the registry signatures of downloaded packages" that "you download from the public npm registry, or any registry that supports signatures". It also verifies the "provenance attestations" of any packages that provide them.

@levinmr levinmr merged commit 4f901ea into develop Nov 18, 2024
15 of 17 checks passed
@levinmr levinmr deleted the audit-signatures-workflow branch November 18, 2024 19:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants