security: stricter pnpm config blockExoticSubdeps & trustPolicy#220
security: stricter pnpm config blockExoticSubdeps & trustPolicy#220Sheraff wants to merge 1 commit into
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe workspace configuration adds two new top-level pnpm settings to enforce stricter dependency management: ChangesWorkspace Dependency Security Settings
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
View your CI Pipeline Execution ↗ for commit 028a254
☁️ Nx Cloud last updated this comment at |
Enables pnpm's no-downgrade trust policy and blocks exotic transitive dependencies via blockExoticSubdeps.
Summary by CodeRabbit