Skip to content

Add --ignore-scripts to npm install in example Dockerfiles#31

Merged
dash14 merged 1 commit intomainfrom
security/add-ignore-scripts-to-examples
Apr 5, 2026
Merged

Add --ignore-scripts to npm install in example Dockerfiles#31
dash14 merged 1 commit intomainfrom
security/add-ignore-scripts-to-examples

Conversation

@dash14
Copy link
Copy Markdown
Owner

@dash14 dash14 commented Apr 5, 2026

Summary

  • Add --ignore-scripts flag to npm install in example Dockerfiles
  • Update CI workflows (example-audit.yml, example-restrict.yml) and Makefile
  • Prevent package lifecycle scripts from running during build, reducing supply chain attack risk

@dash14 dash14 merged commit fb61fb9 into main Apr 5, 2026
6 checks passed
@dash14 dash14 deleted the security/add-ignore-scripts-to-examples branch April 5, 2026 12:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant