-
Notifications
You must be signed in to change notification settings - Fork 30
Description
Story
As developer, I want our CI process to be as safe as possible - particularly, it should not be possible to harvest credentials via infected NPM packages.
Acceptance criteria
- We run
npm installwith disabled scripts.
[TASK] Disable npm post‑install scripts for security reasons #1952 - We run
npm ciinstead ofnpm install. - For NPM, dependabot will only provides updates for packages that are at least 3 weeks old.
[TASK] Let dependabot wait for 3 weeks for NPM updates #1953
Additional information
https://snyk.io/de/articles/npm-security-best-practices-shai-hulud-attack/
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels
Type
Projects
Status
Done