Skip to content

Write safer install instructions in readme - #14

Open
ZelphirKaltstahl wants to merge 1 commit into
git-calendar:mainfrom
ZelphirKaltstahl:main
Open

ZelphirKaltstahl wants to merge 1 commit into
git-calendar:mainfrom
ZelphirKaltstahl:main

Conversation

@ZelphirKaltstahl

Copy link
Copy Markdown

Hi. I just saw your project and when I saw npm install I thought "Argh... This can be done in a safer way."

The background is that with a plain npm install any pre-install scripts of dependencies can run, and in bad cases simply nuke a user's home directory or install malware. You are not controlling all of your dependencies, and neither are you pinning one specific version of your dependencies in package.json, audited to not be harmful, so extra care is needed installing the dependencies.

I have edited the readme to reflect this and install dependencies in a safer way. Your github workflow already does use npm ci though not with the --ignore-scripts flag, but then again that's not running on the user's machine anyway.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant