SIGN IN SIGN UP

ci: add weekly non-blocking pnpm audit (#4766)

Visibility-only audit workflow on a Monday-morning cron. Runs
pnpm audit --audit-level=high with continue-on-error so it surfaces
new advisories in the Actions tab without gating PR merges. Findings
are typically in upstream dev tooling (lerna, nx, commitizen,
vitepress) that we use deliberately and can't fix at the leaf.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
E
escapedcat committed
dc003828d2f5f2e03148135ed256c867ec093c5d
Parent: 345e6f9
Committed by GitHub <noreply@github.com> on 5/12/2026, 2:23:58 PM