paperclip/.github
Dotta 2116570603 Isolate trusted runner reporting dependencies behind an integrity lock
Install only the dedicated reporting runtime with npm ci and disabled lifecycle scripts. Preserve the trusted source checkout, pin all registry artifacts, and execute reporting and publication through the isolated runtime before and after scoped credential exchange.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-12 22:38:31 -05:00
..
ISSUE_TEMPLATE chore(github): expand issue forms (#7628) 2026-06-05 22:27:12 -07:00
scripts ci: keep Cloud readiness markers out of the builder queue (#13330) 2026-09-12 12:32:46 -07:00
storybook-deploy feat: publish CODEOWNER-approved Storybook branch previews (#13226) 2026-09-11 09:13:55 -05:00
workflows Isolate trusted runner reporting dependencies behind an integrity lock 2026-09-12 22:38:31 -05:00
CODEOWNERS chore: add @forgottendev to CODEOWNERS (#12501) 2026-08-29 08:05:43 -05:00
PULL_REQUEST_TEMPLATE.md fix(ci): make PR-template inline-description contract explicit (#10558) 2026-07-31 09:46:26 -07:00
dependabot.yml fix(observability): pin the Sentry browser SDK and gate the optional Sentry server peer on the exact version (#12270) 2026-08-27 07:20:03 -07:00
docker-context-checks.Dockerfile ci: keep traceability regression tests in the Docker build context (#12858) 2026-09-04 16:39:13 -07:00