Make CI validate the same release inputs
Install from the committed lockfile, use a supported pinned runtime, and run lint, typechecking, tests, and build before release. Keep deployment credentials out of untrusted pull-request jobs. Protect the release branch with required checks, and verify that the deployment corresponds to the tested commit. This is guidance for your project pipeline, not a ready-to-copy workflow.
#testing#shipping
Sources
Verified 2026-09-30