Bump the production group across 1 directory with 3 updates #305
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Build | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| permissions: | |
| contents: read | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: actions/setup-node@v7 | |
| with: | |
| node-version: 22 | |
| # `ci`, not `install`: it installs the lockfile exactly and fails if | |
| # package.json has moved away from it. `npm install` is allowed to | |
| # resolve within ranges and rewrite the lockfile, so every green | |
| # build was against whatever npm happened to resolve that morning | |
| # rather than against what is committed. | |
| - run: npm ci --no-audit --no-fund | |
| - run: npm run build |