Drop the standalone npm ci step from the Security Audit workflow; the ./.github/actions/setup-node composite action already runs npm ci --include=dev.
The workflow currently installs dependencies twice (composite action, then a bare npm ci), doubling the job's slowest step for no difference in the audited tree. Remove the redundant step and confirm the job still ends with npm run audit (blocking) followed by the non-blocking dev-inclusive pass.
Expected files to touch: .github/workflows/security-audit.yaml.
Noted in the review of #1172 (pre-existing; intentionally left out of that diff).
Drop the standalone
npm cistep from the Security Audit workflow; the./.github/actions/setup-nodecomposite action already runsnpm ci --include=dev.The workflow currently installs dependencies twice (composite action, then a bare
npm ci), doubling the job's slowest step for no difference in the audited tree. Remove the redundant step and confirm the job still ends withnpm run audit(blocking) followed by the non-blocking dev-inclusive pass.Expected files to touch:
.github/workflows/security-audit.yaml.Noted in the review of #1172 (pre-existing; intentionally left out of that diff).