Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(security): limit installation source #4867

Merged
merged 2 commits into from Nov 21, 2021

Conversation

Jack-Works
Copy link
Member

As discussed in pnpm/pnpm#4001, limiting build scripts is not enough.
It can be bypassed by specifying a non-safe installation target.

This PR adds a PNPM installation hook to validate all those non-safe installation targets.

#3323

@github-actions
Copy link
Contributor

github-actions bot commented Nov 21, 2021

@github-actions github-actions bot temporarily deployed to pull request November 21, 2021 02:11 Inactive
@Jack-Works Jack-Works changed the title feat: limit installation source feat(security): limit installation source Nov 21, 2021
@Jack-Works Jack-Works merged commit 62d27a9 into develop Nov 21, 2021
@Jack-Works Jack-Works deleted the limit-installation-source branch November 21, 2021 02:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant