Skip to content

chore: harden supply chain config#215

Merged
jxom merged 1 commit intomainfrom
georgen/supply-chain-hardening
Apr 15, 2026
Merged

chore: harden supply chain config#215
jxom merged 1 commit intomainfrom
georgen/supply-chain-hardening

Conversation

@grandizzy
Copy link
Copy Markdown
Contributor

  • trustPolicy: permissiveno-downgrade — blocks packages with trust downgrades (possible takeover signal)
  • Added strictDepBuilds: true — fails on unreviewed postinstall scripts instead of warning
  • Moved trust-policy-exclude from .npmrc to pnpm-workspace.yaml trustPolicyExclude (required for no-downgrade to honor excludes)
  • Expanded onlyBuiltDependencies allowlist (bufferutil, cloudflared, cpu-features, protobufjs, sharp, ssh2, utf-8-validate)

Dep updates split out to a follow-up PR.

Prompted by: georgen

- trustPolicy: permissive → no-downgrade (blocks packages with trust downgrades)
- Added strictDepBuilds: true (fails on unreviewed postinstall scripts)
- Moved trust-policy-exclude from .npmrc to pnpm-workspace.yaml trustPolicyExclude
- Expanded onlyBuiltDependencies allowlist (bufferutil, cloudflared, cpu-features, protobufjs, sharp, ssh2, utf-8-validate)

Co-authored-by: grandizzy <38490174+grandizzy@users.noreply.github.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019d9179-c196-7237-b643-008fa871803d
Co-authored-by: Amp <amp@ampcode.com>
@github-actions
Copy link
Copy Markdown
Contributor

Worker Preview
Wagmi https://94e95e0f-accounts-wagmi.porto.workers.dev

@pkg-pr-new
Copy link
Copy Markdown

pkg-pr-new bot commented Apr 15, 2026

Open in StackBlitz

npm i https://pkg.pr.new/tempoxyz/accounts@215

commit: 76365be

@github-actions
Copy link
Copy Markdown
Contributor

Worker Preview
Playground https://e0a6e606-accounts-playground.porto.workers.dev

@grandizzy grandizzy requested review from horsefacts and jxom April 15, 2026 14:54
@grandizzy grandizzy self-assigned this Apr 15, 2026
@jxom jxom merged commit 72da489 into main Apr 15, 2026
10 checks passed
@jxom jxom deleted the georgen/supply-chain-hardening branch April 15, 2026 23:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants