Skip to content

Require approval for dependency install scripts - #98

Merged
jstayton merged 1 commit into
developmentfrom
require-install-script-approval
Oct 6, 2026
Merged

jstayton merged 1 commit into
developmentfrom
require-install-script-approval

Conversation

@jstayton

@jstayton jstayton commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Only reviewed dependencies may run install scripts, using npm's allowScripts and strict-allow-scripts. Both current ones come in through Jest:

  1. unrs-resolver is approved, pinned to its reviewed version. Its postinstall checks for its platform's native binding and downloads it if missing.
  2. @parcel/watcher is denied. Its install script only builds from source when npm_config_build_from_source is set; otherwise the prebuilt binary comes from an optional platform package.

Updating unrs-resolver fails the install until it's re-approved with npm approve-scripts unrs-resolver, which is noted in AGENTS.md. .npmrc isn't in files, and npm only reads allowScripts from the root project, so consumers aren't affected.

npm 11.19+ enforces it, which covers the Node 24 and 26 CI jobs. Node 22's npm 10 warns about an unknown config and ignores it.

🤖 Generated with Claude Code

Only reviewed dependencies may run install scripts. unrs-resolver is
approved, pinned to its reviewed version, so updating it fails the
install until it's re-approved. @parcel/watcher is denied, since it
ships prebuilt binaries and only builds from source on request. npm
11.19+ enforces it; npm 10 (Node 22) warns about an unknown config and
ignores it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@jstayton
jstayton force-pushed the require-install-script-approval branch from ab75119 to 68af881 Compare October 6, 2026 12:03
@jstayton
jstayton merged commit 607a1a0 into development Oct 6, 2026
5 checks passed
@jstayton
jstayton deleted the require-install-script-approval branch October 6, 2026 12:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant