Dev Dependency Updates #302
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This pull request introduces several improvements to CI workflows, dependency updates, and documentation. The main changes include adding a new OSSF Scorecard workflow to enhance supply-chain security, updating dependencies (notably
htmlhint
), and ensuring all GitHub Actions use pinned versions for better reliability and security.CI/CD and Security Enhancements
.github/workflows/ossf-scorecard.yml
to run OSSF Scorecard analysis on the repository, improving supply-chain security by regularly assessing best practices and uploading results to code scanning.codeql-action
andpublish-vscode-extension
, to prevent breaking changes from upstream updates. [1] [2] [3]Dependency Updates
htmlhint
from version 1.6.3 to 1.7.0 in bothhtmlhint
andhtmlhint-server
packages, updating all relevant references inpackage.json
andpackage-lock.json
files. [1] [2] [3] [4] [5] [6] [7]>=20
to>=18
in bothhtmlhint
andhtmlhint-server
to increase compatibility. [1] [2]package.json
from 22.16.0 to 22.19.0.Documentation and Miscellaneous
.github/copilot-instructions.md
with best practices for GitHub Actions, including workflow placement, naming conventions, version pinning, and security recommendations."ossf"
to the list of allowed words in.cspell.json
to prevent spellcheck errors.