Comments (4)
Looks like these are ALL actually for the bundled pnpm.js
file, which may be from the actual pnpm repo?
from action-setup.
Can you create a PR that setups Code Scanning for all files except dist
and pnpm.js
?
from action-setup.
Can you create a PR that setups Code Scanning for all files except
dist
andpnpm.js
?
It looks like there's a way to set up "advanced code scanning", which is effectively just a workflow file. Looking at the options for this though, I'm not noticing any options for filtering out which files to scan. I'm looking through the "Configuring advanced setup" and "Customizing code scanning" sections - do you see anything I'm missing?
I imagine (if you don't find anything) that the idea is if you don't scan a part of a repository for code security scanning, then that kinda defeats the purpose, since there will always be some part of the repo that won't be secure 😅
from action-setup.
I imagine (if you don't find anything) that the idea is if you don't scan a part of a repository for code security scanning
Ah, I see. Then we would have to update the pnpm.js
to the latest version, assuming pnpm itself passes the code scanning.
from action-setup.
Related Issues (20)
- Build script fails with "Cannot augment module '_' with value exports because it resolves to a non-module entity."
- How to add personal access tokens as environment variables to a action ? HOT 3
- Action is not verified in Github Marketplace HOT 4
- Support pnpm 8 HOT 3
- The inferred type of "X" cannot be named without a reference to "Y". This is likely not portable. A type annotation is necessary.
- Feature Request: add builtin cache support HOT 3
- Using pnpm/action-setup in a subdirectory of a git repoository is giving: ENOENT: no such file or directory HOT 10
- [Q] Setup Node Cache HOT 4
- Parse package.json from subfolder HOT 1
- [feature request] Use version of pnpm specified in package.json's engines section HOT 1
- Make `version` optional HOT 2
- The version of pnpm is not being retrieved from the packageManager field in the package.json. HOT 6
- How to cache pnpm ? HOT 1
- README references old versions of pnpm
- Installing pnpm when the package.json isn't in the root directory HOT 3
- `v2` not up to date HOT 5
- Invalid
- EACCES: permission denied when running in a container w/ non-default user
- node20 support HOT 18
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from action-setup.