Skip to content

Disable npm lifecycle scripts and npx for security#1851

Closed
jespino wants to merge 6 commits into
mainfrom
pde-128-disable-npm-scripts
Closed

Disable npm lifecycle scripts and npx for security#1851
jespino wants to merge 6 commits into
mainfrom
pde-128-disable-npm-scripts

Conversation

@jespino
Copy link
Copy Markdown

@jespino jespino commented Dec 12, 2025

  • Add npm/yarn ignore-scripts config to Dockerfile
  • Disable npx in postCreateCommand

Related to PDE-128

- Add npm/yarn ignore-scripts config to Dockerfile
- Disable npx in postCreateCommand

Related to PDE-128

Co-authored-by: Ona <no-reply@ona.com>
@jespino jespino requested a review from a team as a code owner December 12, 2025 17:31
jespino and others added 4 commits December 12, 2025 17:34
Co-authored-by: Ona <no-reply@ona.com>
- Add package.json and package-lock.json in .autofix directory
- Update workflow to use npm ci with lockfile for reproducible builds

Co-authored-by: Ona <no-reply@ona.com>
Co-authored-by: Ona <no-reply@ona.com>
Co-authored-by: Ona <no-reply@ona.com>
@geropl
Copy link
Copy Markdown
Member

geropl commented Dec 19, 2025

@jespino can you rebase please? the build issues should be resolved now

@geropl
Copy link
Copy Markdown
Member

geropl commented Dec 19, 2025

@jespino same here, rebuild should fix these

@jespino
Copy link
Copy Markdown
Author

jespino commented Dec 19, 2025

@geropl CI passes, we can merged this whenever you want

@kylos101
Copy link
Copy Markdown
Collaborator

Closing given conversation with @geropl earlier today

@kylos101 kylos101 closed this Jan 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants