Skip to content

Security fix#126

Merged
jbum merged 1 commit intomainfrom
jbum-security-fix
Mar 29, 2026
Merged

Security fix#126
jbum merged 1 commit intomainfrom
jbum-security-fix

Conversation

@jbum
Copy link
Copy Markdown
Contributor

@jbum jbum commented Mar 29, 2026

Modified deploy scripts to use npm ci instead of npm install.

This is to prevent accidental installation of a package version later than the one currently used in package-lock.json, which is an avenue thru which compromised packages can be installed.

@github-actions
Copy link
Copy Markdown

Preview site available at jbum-security-fix.pr.engaged.ca.gov.

@jbum jbum merged commit 826d6c8 into main Mar 29, 2026
1 check passed
@jbum jbum deleted the jbum-security-fix branch March 29, 2026 14:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant