Skip to content

ci: add ignore-scripts to Node package manager config (20260527-155623)#219

Merged
derekmisler merged 1 commit into
mainfrom
sec-cli/ignore-scripts-fix-20260527-155623
May 27, 2026
Merged

ci: add ignore-scripts to Node package manager config (20260527-155623)#219
derekmisler merged 1 commit into
mainfrom
sec-cli/ignore-scripts-fix-20260527-155623

Conversation

@securityeng-bot
Copy link
Copy Markdown
Contributor

This PR was generated by sec-cli github repositories ignore-scripts update.

What changed

Package managers detected: pnpm

Updated config files (directive appended):

  • .npmrc

Why

Running npm install (or yarn, pnpm, bun, npx) without restricting
postinstall scripts allows dependency lifecycle hooks to execute arbitrary code
during installation. Setting ignore-scripts=true (or the equivalent for your
package manager) mitigates this risk.

References:

@derekmisler derekmisler merged commit 2543278 into main May 27, 2026
14 checks passed
@derekmisler derekmisler deleted the sec-cli/ignore-scripts-fix-20260527-155623 branch May 27, 2026 16:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant