Skip to content

Conversation

IvanGoncharov
Copy link
Member

Motivation: increase security.
Discovered while looking into #3162

@netlify
Copy link

netlify bot commented Aug 16, 2022

Deploy Preview for compassionate-pike-271cb3 ready!

Name Link
🔨 Latest commit 48e56cd
🔍 Latest deploy log https://app.netlify.com/sites/compassionate-pike-271cb3/deploys/62fbd7672cdeff0008dc091b
😎 Deploy Preview https://deploy-preview-3699--compassionate-pike-271cb3.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.

@github-actions
Copy link

Hi @IvanGoncharov, I'm @github-actions bot happy to help you with this PR 👋

Supported commands

Please post this commands in separate comments and only one per comment:

  • @github-actions run-benchmark - Run benchmark comparing base and merge commits for this PR
  • @github-actions publish-pr-on-npm - Build package from this PR and publish it on NPM

Motivation: increase security.
Discovered while looking into graphql#3162
@IvanGoncharov
Copy link
Member Author

Also, it reduces pressure on maintainers to review PRs that add new dependencies.
We only have devDependencies, but they can still compromise developer machines (e.g., still GH or NPM keys) or compromise code inside the published NPM package.

@IvanGoncharov IvanGoncharov merged commit 9a494d9 into graphql:main Aug 16, 2022
@IvanGoncharov IvanGoncharov deleted the pr_branch4 branch August 16, 2022 17:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant