Skip to content

SCANNPM-123 Use public npm urls in package-lock.json#355

Merged
vdiez merged 1 commit intomasterfrom
public-npm-repo
Dec 1, 2025
Merged

SCANNPM-123 Use public npm urls in package-lock.json#355
vdiez merged 1 commit intomasterfrom
public-npm-repo

Conversation

@vdiez
Copy link
Contributor

@vdiez vdiez commented Dec 1, 2025

No description provided.

@vdiez vdiez requested a review from jdkandersson December 1, 2025 15:18
@hashicorp-vault-sonar-prod hashicorp-vault-sonar-prod bot changed the title Use public npm urls in package-lock.json SCANNPM-123 Use public npm urls in package-lock.json Dec 1, 2025
@hashicorp-vault-sonar-prod
Copy link

hashicorp-vault-sonar-prod bot commented Dec 1, 2025

SCANNPM-123

@sonarqubecloud
Copy link

sonarqubecloud bot commented Dec 1, 2025

SonarQube reviewer guide

Summary: Migrates package registry from repox.jfrog.io to registry.npmjs.org and removes npm workflow config

Review Focus:

  • Verify all package registry URLs have been completely updated (thousands of lines changed)
  • Ensure no hardcoded references to the old JFrog registry remain
  • Check for any package integrity/hash issues that may arise from registry change
  • Confirm the removal of .github/workflows/.npmrc won't break CI/CD authentication flows

Start review at: .github/workflows/.npmrc (deleted file). Important to verify this authentication config removal is intentional and that CI/CD pipelines have alternative auth mechanisms in place, as this could break automated npm operations.

💬 Please send your feedback

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

@vdiez vdiez enabled auto-merge (squash) December 1, 2025 15:22
@vdiez vdiez merged commit 28b3f52 into master Dec 1, 2025
8 checks passed
@vdiez vdiez deleted the public-npm-repo branch December 1, 2025 15:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants