Files
David Abutbul f76824bdb6 ci(skills): pin clawhub CLI by hash via committed lockfile
Scorecard flags the skill-release workflow's npm install of the clawhub
CLI (code-scanning alerts #25/#26): version pinning alone carries no
integrity guarantee. Install it with npm ci from a committed
package-lock.json instead, so every package (clawhub + 35 transitive
deps) is verified against its sha512 hash at install time.

The publish-payload patch step now resolves the module from the local
node_modules instead of npm root -g.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-11 14:39:56 +03:00
..
2026-02-05 21:58:23 +02:00
2026-02-16 16:00:43 +02:00
2026-02-05 21:58:23 +02:00