mirror of
https://github.com/astral-sh/setup-uv.git
synced 2026-09-02 21:59:22 +00:00
Harden npm install defaults (#1026)
CI already disables npm lifecycle scripts, but ordinary installs from the repository still run them. Set `ignore-scripts = true` in `.npmrc` so developer and maintenance installs use the same default. Keep the existing seven-day `min-release-age` policy for new resolutions. Require `npm>=11.10.0` through `engines.npm` and `engine-strict`, while retaining `devEngines` for newer clients; older installers can otherwise ignore `devEngines` and the age setting. Pin the build and checksum workflows to Node.js `24.19.0` so their bundled `npm` supports the policy. Explicit project commands such as `npm run package` remain available. Related: astral-sh/ruff-action#401 applies the matching `npm` defaults, and astral-sh/ruff-action#411 adds the same legacy-aware version floor. astral-sh/ruff#27837 applies the install-script default to Ruff's JavaScript projects. astral-sh/setup-uv#1027 separately adds registry-signature and provenance verification. --------- Co-authored-by: zaniebot <242828183+zaniebot@users.noreply.github.com>
This commit is contained in:
Generated
+3
@@ -30,6 +30,9 @@
|
||||
"js-yaml": "^5.2.3",
|
||||
"ts-jest": "^29.4.11",
|
||||
"typescript": "^6.0.3"
|
||||
},
|
||||
"engines": {
|
||||
"npm": ">=11.10.0"
|
||||
}
|
||||
},
|
||||
"node_modules/@actions/cache": {
|
||||
|
||||
@@ -5,6 +5,16 @@
|
||||
"type": "module",
|
||||
"description": "Set up your GitHub Actions workflow with a specific version of uv",
|
||||
"main": "dist/setup/index.cjs",
|
||||
"engines": {
|
||||
"npm": ">=11.10.0"
|
||||
},
|
||||
"devEngines": {
|
||||
"packageManager": {
|
||||
"name": "npm",
|
||||
"version": ">=11.10.0",
|
||||
"onFail": "error"
|
||||
}
|
||||
},
|
||||
"scripts": {
|
||||
"build": "tsc --noEmit",
|
||||
"check": "biome check --write",
|
||||
|
||||
Reference in New Issue
Block a user