Skip to content

fix(PLT-3359): harden yarn configuration#15

Open
tf-seti wants to merge 1 commit intomainfrom
appsec/harden-yarn-config
Open

fix(PLT-3359): harden yarn configuration#15
tf-seti wants to merge 1 commit intomainfrom
appsec/harden-yarn-config

Conversation

@tf-seti
Copy link
Copy Markdown
Contributor

@tf-seti tf-seti commented Apr 1, 2026

Harden yarn configuration

This PR hardens yarn configuration against supply chain attacks.

Changes

  • .yarnrc: Added ignore-scripts true and save-exact true.
  • Dependabot: Added a 7-day cooldown for third-party npm updates (excluding @typeform/*).
  • Compatibility: Maintained semantic-release version locks for Node 22 compatibility.

Automated by Application Security · supply-chain-hardening

Created by Sourcegraph batch change david.salvador/harden-yarn-config.

@tf-seti tf-seti changed the title fix(NOJIRA-1234): harden yarn configuration fix(PLT-3359): harden yarn configuration Apr 28, 2026
@tf-seti tf-seti force-pushed the appsec/harden-yarn-config branch from 85fa8e9 to 5ea628d Compare April 28, 2026 09:00
@tf-seti tf-seti marked this pull request as ready for review April 28, 2026 09:34
@tf-seti tf-seti requested a review from a team as a code owner April 28, 2026 09:34
@pr-auditor
Copy link
Copy Markdown

pr-auditor Bot commented Apr 28, 2026

✅ Security Analysis Results

Great news! No security issues found in this pull request.

Analysis Summary:

  • 📁 Files reviewed: 2
  • ✅ No security vulnerabilities detected

Security analysis powered by Claude Sonnet 4.6 via pr-auditor | Questions? Contact #dx-team or check out this page

@gitstream-cm
Copy link
Copy Markdown

gitstream-cm Bot commented Apr 28, 2026

🥷 Code experts: pannago

pannago has most 👩‍💻 activity in the files.
pannago has most 🧠 knowledge in the files.

See details

.github/dependabot.yml

Activity based on git-commit:

pannago
APR 25 additions & 0 deletions
MAR
FEB
JAN
DEC
NOV

Knowledge based on git-blame:
pannago: 100%

✨ Comment /gs review for LinearB AI review. Learn how to automate it here.

@tf-seti tf-seti force-pushed the appsec/harden-yarn-config branch from 5ea628d to 4381ee0 Compare April 28, 2026 10:27
@typeform-ops-gha
Copy link
Copy Markdown

[BOT] Preview available with hash 2d54c2484239dda4345a9cab534026df02eff6d5 here.

@sonarqubecloud
Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants