Skip to content

CLOUDPLAT-3162: add npm-release environment gate (dynamodb-replicator)#119

Open
haseebehsan wants to merge 1 commit into
masterfrom
cloudplat-3162/npm-release-env
Open

CLOUDPLAT-3162: add npm-release environment gate (dynamodb-replicator)#119
haseebehsan wants to merge 1 commit into
masterfrom
cloudplat-3162/npm-release-env

Conversation

@haseebehsan

@haseebehsan haseebehsan commented Jun 23, 2026

Copy link
Copy Markdown
Contributor

Adding environment: npm-release to the npm release workflow.

@haseebehsan haseebehsan added the ai AI coding agents co-authored the code label Jun 23, 2026
@haseebehsan haseebehsan requested a review from a team as a code owner June 23, 2026 14:51
@haseebehsan haseebehsan added the ai AI coding agents co-authored the code label Jun 23, 2026
@ox-security

ox-security Bot commented Jun 23, 2026

Copy link
Copy Markdown

OX Security Logo

Successfully scanned changes introduced in a pull request into master from cloudplat-3162/npm-release-env.

Internal scan identifier: ca7b3f82-408d-4d43-9607-357886c91aed.

Total issues Blocking issues Scan status
1 0 ✔️
Category Issues
CI/CD Posture 1

See all issues found during this scan in the OX Security Application.

Detailed information
Issue #1
NameUnpinned Reusable Workflow • GitHub Actions
StatusOld
EnforcementMonitor
SeverityHigh
CategoryCI/CD Posture
Source toolsOX CI/CD Posture
RecommendationPin reusable workflows to a full-length commit SHA (40 characters) instead of a tag or branch. Example: uses: org/repo/.github/workflows/build.yml@a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0
1 aggregation
FileMatch
.github/workflows/npm-release.ymluses: mapbox/gha-public/.github/workflows/workflow-npm-oidc-publish.yml@main

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai AI coding agents co-authored the code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants