fastify-vite icon indicating copy to clipboard operation
fastify-vite copied to clipboard

ci(ci): ignore scripts

Open Fdawgs opened this issue 7 months ago • 3 comments

Add the --ignore-scripts arg to disable the execution of any scripts by third-party packages.

See https://snyk.io/blog/npm-security-preventing-supply-chain-attacks/

Checklist

Fdawgs avatar May 05 '25 13:05 Fdawgs

⚠️ No Changeset found

Latest commit: 4a06904ef957ee77617a0ebf660a9530db1dfcb8

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

changeset-bot[bot] avatar May 05 '25 13:05 changeset-bot[bot]

Deploy Preview for agitated-mahavira-26f8f9 canceled.

Name Link
Latest commit 4a06904ef957ee77617a0ebf660a9530db1dfcb8
Latest deploy log https://app.netlify.com/sites/agitated-mahavira-26f8f9/deploys/6818b7d37df7a50008dd6505

netlify[bot] avatar May 05 '25 13:05 netlify[bot]

I think we can get this for free by upgrading to pnpm 10.x

onlywei avatar May 05 '25 14:05 onlywei