Completes the allowScripts rollout: upgrade CI npm to the 11.x line (node 22 bundles 10.x, which predates the gate) with a loud version guard so the flag can never silently degrade into a warning, then run npm ci --strict-allow-scripts. A dependency that introduces install scripts not covered by the committed policy now fails the job with npm's approve-scripts/deny-scripts instructions; the pre-commit sync hook keeps existing pins fresh after bumps. |
||
|---|---|---|
| .. | ||
| ISSUE_TEMPLATE | ||
| scripts | ||
| workflows | ||
| CODEOWNERS | ||
| dependabot.yml | ||
| FUNDING.yml | ||