Skip to content

chore: use npm ci --ignore-scripts everywhere#699

Merged
eifinger merged 1 commit intoastral-sh:mainfrom
woodruffw-forks:ww/npm
Dec 2, 2025
Merged

chore: use npm ci --ignore-scripts everywhere#699
eifinger merged 1 commit intoastral-sh:mainfrom
woodruffw-forks:ww/npm

Conversation

@woodruffw
Copy link
Member

Like astral-sh/ruff-action#276 🙂

This also adds cooldown stanzas to the Dependabot updater rules: this ensures that we only receive dependency bumps once they're at least a week old, which should reduce the window of opportunity for an attacker who temporarily compromises popular packages (like with "Shai-Hulud" last week).

Signed-off-by: William Woodruff <william@astral.sh>
@woodruffw woodruffw self-assigned this Dec 1, 2025
@woodruffw woodruffw requested a review from eifinger as a code owner December 1, 2025 22:48
Copy link
Collaborator

@eifinger eifinger left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Awesome thank you @woodruffw 🔒

@eifinger eifinger merged commit 64f7f4e into astral-sh:main Dec 2, 2025
90 checks passed
@eifinger eifinger added the ci Pull requests that change the CI workflows label Dec 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci Pull requests that change the CI workflows

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants