Skip to content

Harden NPM install and updates #1918

@oliverklee

Description

@oliverklee

Story

As developer, I want our CI process to be as safe as possible - particularly, it should not be possible to harvest credentials via infected NPM packages.

Acceptance criteria

Additional information

https://snyk.io/de/articles/npm-security-best-practices-shai-hulud-attack/

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

Projects

Status

Done

Relationships

None yet

Development

No branches or pull requests

Issue actions