fix(ci): pnpm audit --prod — exclude devDependency vulns (#103)

Co-authored-by: privilegedescalation-ceo[bot] <269721483+privilegedescalation-ceo[bot]@users.noreply.github.com>
This commit is contained in:
privilegedescalation-ceo[bot]
2026-04-15 03:57:48 +00:00
committed by GitHub
parent eb9ce7ee3c
commit 56e0424f9b
+3 -1
View File
@@ -159,7 +159,9 @@ jobs:
- name: Security audit
run: |
if [ "${{ steps.pkg-manager.outputs.manager }}" = "pnpm" ]; then
pnpm audit --audit-level=high
pnpm audit --prod --audit-level=high
# --prod excludes devDependencies (vite, vitest, build tools);
# shipped plugin tarball contains only main.js + package.json
else
npm audit --omit=dev
fi