Skip to content

chore: add ghostdeps advisory ci - #221

Closed
rowkav09 wants to merge 1 commit into
Redocly:mainfrom
rowkav09:add-ghostdeps-advisory-ci
Closed

rowkav09 wants to merge 1 commit into
Redocly:mainfrom
rowkav09:add-ghostdeps-advisory-ci

Conversation

@rowkav09

Copy link
Copy Markdown

What/Why/How?

ran my dependency checker (ghost-deps) on openapi-sampler after the move to Rollup. it flags babel-loader, json-loader and core-js as unused dev dependencies. i couldn't find references outside package.json and the lockfile; the current build uses Rollup, not webpack.

this adds ghost-deps as an advisory CI check, without removing any packages or failing your build. i'm the author of ghost-deps. if this isn't useful here, no worries.

Testing

workflow-only change; no dependency removal tested. the finding is from a static scan and source/config review.

Security

uses pinned action and checkout commits with scoped workflow permissions; no repository code changes.

@rowkav09
rowkav09 requested a review from a team as a code owner September 29, 2026 19:47
@rowkav09 rowkav09 closed this Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant