Skip to content

fix: #2030 add ignore script prevent supply chain attack#859

Merged
DerekRoberts merged 4 commits intomainfrom
fix/2030-add-ignore-script-prevent-supply-chain-attack
Nov 27, 2025
Merged

fix: #2030 add ignore script prevent supply chain attack#859
DerekRoberts merged 4 commits intomainfrom
fix/2030-add-ignore-script-prevent-supply-chain-attack

Conversation

@ianliuwk1019
Copy link
Contributor

@ianliuwk1019 ianliuwk1019 commented Nov 27, 2025

Re: Shai Hulud 2
Fix: via @basilv
This PR implements a security mitigation against the Shai Hulud 2 npm supply chain attack by adding the --ignore-scripts flag to npm ci commands across build environments. This prevents potentially malicious install scripts from executing during package installation.


Thanks for the PR!

Deployments, as required, will be available below:

Please create PRs in draft mode. Mark as ready to enable:

After merge, new images are deployed in:

@ianliuwk1019 ianliuwk1019 changed the title Fix/2030 add ignore script prevent supply chain attack fix: #2030 add ignore script prevent supply chain attack Nov 27, 2025
@DerekRoberts DerekRoberts merged commit 4374793 into main Nov 27, 2025
23 checks passed
@DerekRoberts DerekRoberts deleted the fix/2030-add-ignore-script-prevent-supply-chain-attack branch November 27, 2025 20:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants