Skip to content

chore: harden supply chain security#11

Open
nick134-bit wants to merge 5 commits into
mainfrom
chore/hardening-deps-pipeline
Open

chore: harden supply chain security#11
nick134-bit wants to merge 5 commits into
mainfrom
chore/hardening-deps-pipeline

Conversation

@nick134-bit
Copy link
Copy Markdown

Add nonce-based CSP via middleware to block injected scripts, thread
nonce through to the inline theme script, add HSTS/Referrer/Permissions
policy headers, pin pnpm@9.15.4 and upgrade Node 19→22 in Dockerfile,
pin actions/checkout to commit SHA, add .npmrc with audit-level=high,
and enforce a 7-day minimum package age via pnpm-workspace.yaml.

Add nonce-based CSP via middleware to block injected scripts, thread
  nonce through to the inline theme script, add HSTS/Referrer/Permissions
  policy headers, pin pnpm@9.15.4 and upgrade Node 19→22 in Dockerfile,
  pin actions/checkout to commit SHA, add .npmrc with audit-level=high,
  and enforce a 7-day minimum package age via pnpm-workspace.yaml.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant