Skip to content

[Chore] CSO remediations: pin CI actions, drop unused blendavit npm dep #551

@Dr-kersho

Description

@Dr-kersho

Driver

Follow-up from /gstack-cso daily audit (2026-06-06).

Scope

  1. Pin third-party and first-party GitHub Actions to immutable commit SHAs in .github/workflows/.
  2. Remove unused animejs npm dependency from blendavit static site (not loaded in shipped HTML).

Acceptance criteria

  • All workflow uses: references use full SHAs with version comments
  • projects/smartmomlabs/website/package.json removed (zero runtime npm deps)
  • node_modules/ gitignored under blendavit website

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions