chore: move security audit from dev/staging to production workflow#358
chore: move security audit from dev/staging to production workflow#358
Conversation
Remove pnpm audit gate from bridge-explorer-develop-staging.yml to unblock rapid iteration on develop and staging environments. Add the same audit job to publish-ghcr-image-release.yml so production releases (version tags) remain gated behind a high-severity dependency check.
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub. |
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Remove pnpm audit gate from bridge-explorer-develop-staging.yml to unblock rapid iteration on develop and staging environments. Add the same audit job to publish-ghcr-image-release.yml so production releases (version tags) remain gated behind a high-severity dependency check.