Skip to content

Conversation

@sapphi-red
Copy link
Member

Description

To avoid cache poisoning (https://docs.zizmor.sh/audits/#cache-poisoning)

@sapphi-red sapphi-red added the p1-chore Doesn't change code behavior (priority) label Sep 18, 2025
Copy link
Contributor

@hi-ogawa hi-ogawa left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

setup-node@v5 will enables caching automatically, so we need to make sure package-manager-cache: false explicitly https://github.com/actions/setup-node/releases/tag/v5.0.0

@sapphi-red sapphi-red merged commit 6901fdb into vitejs:main Sep 18, 2025
12 checks passed
@sapphi-red sapphi-red deleted the ci/disable-pnpm-cache-when-publishing branch September 18, 2025 08:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

p1-chore Doesn't change code behavior (priority)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants