Harden npm install defaults (#1026)

CI already disables npm lifecycle scripts, but ordinary installs from
the repository still run them. Set `ignore-scripts = true` in `.npmrc`
so developer and maintenance installs use the same default. Keep the
existing seven-day `min-release-age` policy for new resolutions. Require
`npm>=11.10.0` through `engines.npm` and `engine-strict`, while
retaining `devEngines` for newer clients; older installers can otherwise
ignore `devEngines` and the age setting. Pin the build and checksum
workflows to Node.js `24.19.0` so their bundled `npm` supports the
policy. Explicit project commands such as `npm run package` remain
available.

Related: astral-sh/ruff-action#401 applies the matching `npm` defaults,
and astral-sh/ruff-action#411 adds the same legacy-aware version floor.
astral-sh/ruff#27837 applies the install-script default to Ruff's
JavaScript projects. astral-sh/setup-uv#1027 separately adds
registry-signature and provenance verification.

---------

Co-authored-by: zaniebot <242828183+zaniebot@users.noreply.github.com>
This commit is contained in:
zaniebot
2026-08-20 17:38:03 +02:00
committed by GitHub
co-authored by zaniebot
parent 7211c71869
commit 19b4d1e990
4 changed files with 16 additions and 1 deletions
+2
View File
@@ -1 +1,3 @@
engine-strict = true
ignore-scripts = true
min-release-age = 7
+1 -1
View File
@@ -1 +1 @@
24
24.19.0
+3
View File
@@ -30,6 +30,9 @@
"js-yaml": "^5.2.3",
"ts-jest": "^29.4.11",
"typescript": "^6.0.3"
},
"engines": {
"npm": ">=11.10.0"
}
},
"node_modules/@actions/cache": {
+10
View File
@@ -5,6 +5,16 @@
"type": "module",
"description": "Set up your GitHub Actions workflow with a specific version of uv",
"main": "dist/setup/index.cjs",
"engines": {
"npm": ">=11.10.0"
},
"devEngines": {
"packageManager": {
"name": "npm",
"version": ">=11.10.0",
"onFail": "error"
}
},
"scripts": {
"build": "tsc --noEmit",
"check": "biome check --write",