fix(security): clear the image scan alerts (#381)

Build git-lfs with Go 1.25.14, stop serving the runner stage from the
layer cache so Debian security updates land, move typescript and
@astrojs/check out of the shipped dependencies, bump the nested copies
of browserslist, js-yaml, nanoid and sharp to patched versions, and
update browserslist in the website lockfile.

Claude-Session: https://claude.ai/code/session_01Tp9pmi65a8k5jLMQFLf4JX
This commit is contained in:
ARUNAVO RAY
2026-09-02 16:16:46 +05:30
committed by GitHub
parent 26f78e06b8
commit a1ff0433df
6 changed files with 195 additions and 179 deletions
+4
View File
@@ -135,6 +135,8 @@ jobs:
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
cache-from: type=gha
# The runner stage installs Debian security updates; never serve it from cache.
no-cache-filters: runner
cache-to: type=gha,mode=max
provenance: false # Disable provenance to avoid unknown/unknown
sbom: false # Disable sbom to avoid unknown/unknown
@@ -149,6 +151,8 @@ jobs:
load: true
tags: gitea-mirror:scan
cache-from: type=gha
# The runner stage installs Debian security updates; never serve it from cache.
no-cache-filters: runner
provenance: false # Disable provenance to avoid unknown/unknown
sbom: false # Disable sbom to avoid unknown/unknown