Skip to content

CLOUDPLAT-3162: add npm-release environment gate (cfn-config)#211

Merged
haseebehsan merged 1 commit into
masterfrom
cloudplat-3162/npm-release-env
Jun 24, 2026
Merged

CLOUDPLAT-3162: add npm-release environment gate (cfn-config)#211
haseebehsan merged 1 commit into
masterfrom
cloudplat-3162/npm-release-env

Conversation

@haseebehsan

@haseebehsan haseebehsan commented Jun 23, 2026

Copy link
Copy Markdown
Contributor

Adding environment: npm-release to the npm release workflow.

@haseebehsan haseebehsan added the ai AI coding agents co-authored the code label Jun 23, 2026
@haseebehsan haseebehsan requested a review from a team as a code owner June 23, 2026 14:51
@haseebehsan haseebehsan added the ai AI coding agents co-authored the code label Jun 23, 2026
@ox-security

ox-security Bot commented Jun 23, 2026

Copy link
Copy Markdown

OX Security Logo

Successfully scanned changes introduced in a pull request into master from cloudplat-3162/npm-release-env.

Internal scan identifier: 8349f69a-e395-4443-99bd-3b246b61c65e.

Total issues Blocking issues Scan status
1 0 ✔️
Category Issues
CI/CD Posture 1

See all issues found during this scan in the OX Security Application.

Detailed information
Issue #1
NameUnpinned Reusable Workflow • GitHub Actions
StatusOld
EnforcementMonitor
SeverityHigh
CategoryCI/CD Posture
Source toolsOX CI/CD Posture
RecommendationPin reusable workflows to a full-length commit SHA (40 characters) instead of a tag or branch. Example: uses: org/repo/.github/workflows/build.yml@a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0
1 aggregation
FileMatch
.github/workflows/npm-release.ymluses: mapbox/gha-public/.github/workflows/workflow-npm-oidc-publish.yml@main

@haseebehsan haseebehsan merged commit e388233 into master Jun 24, 2026
4 checks passed
@haseebehsan haseebehsan deleted the cloudplat-3162/npm-release-env branch June 24, 2026 08:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai AI coding agents co-authored the code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants