Skip to content

Commit 532361c

Browse files
committed
LAM-2559 Security Fix GitHub Actions
1 parent 9f9a0e8 commit 532361c

1 file changed

Lines changed: 9 additions & 7 deletions

File tree

.github/workflows/publish.yml

Lines changed: 9 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -13,11 +13,13 @@ jobs:
1313
steps:
1414
# Step 1: Checkout the code
1515
- name: Checkout repository
16-
uses: actions/checkout@v4
16+
uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
17+
with:
18+
persist-credentials: false
1719

1820
# Step 2: Set up Node.js
1921
- name: Setup Node.js
20-
uses: actions/setup-node@v4
22+
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
2123
with:
2224
node-version: '20' # Adjust Node.js version as needed
2325
registry-url: https://registry.npmjs.org/
@@ -42,13 +44,13 @@ jobs:
4244
- name: Publish to npm
4345
run: npm publish
4446
env:
45-
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
47+
NODE_AUTH_TOKEN: "${{ secrets.NPM_TOKEN }}"
4648

4749
# Step 8: Create a GitHub release (optional)
4850
- name: Create GitHub Release
49-
uses: softprops/action-gh-release@v1
51+
uses: softprops/action-gh-release@a06a81a03ee405af7f2048a818ed3f03bbf83c7b # v2.5.0
5052
with:
51-
tag_name: ${{ github.ref_name }}
52-
name: ${{ github.ref_name }}
53+
tag_name: "${{ github.ref_name }}"
54+
name: "${{ github.ref_name }}"
5355
env:
54-
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
56+
GITHUB_TOKEN: "${{ secrets.GITHUB_TOKEN }}"

0 commit comments

Comments
 (0)