Skip to content

docs: add private vulnerability reporting #3

docs: add private vulnerability reporting

docs: add private vulnerability reporting #3

Workflow file for this run

name: CI
on:
push:
branches:
- main
pull_request:
permissions:
contents: read
concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
local-server:
name: Local stdio server
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Check out repository
uses: actions/checkout@v4
- name: Set up Node.js
uses: actions/setup-node@v4
with:
node-version: 22.12.0
cache: npm
cache-dependency-path: package-lock.json
- name: Install dependencies
run: npm ci
- name: Run checks
run: npm run check
- name: Inspect package contents
run: npm pack --dry-run
- name: Audit production dependencies
run: npm audit --omit=dev --audit-level=high
hosted-worker:
name: Hosted Worker
runs-on: ubuntu-latest
timeout-minutes: 15
defaults:
run:
working-directory: chatgpt-plugin
steps:
- name: Check out repository
uses: actions/checkout@v4
- name: Set up Node.js
uses: actions/setup-node@v4
with:
node-version: 22.18.0
cache: npm
cache-dependency-path: chatgpt-plugin/package-lock.json
- name: Install dependencies
run: npm ci
- name: Type-check
run: npm run check
- name: Run tests
run: npm test
- name: Validate Worker bundle
run: npm run deploy:dry-run
- name: Audit production dependencies
run: npm audit --omit=dev --audit-level=high