-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy path.npmrc
More file actions
24 lines (23 loc) · 1.06 KB
/
Copy path.npmrc
File metadata and controls
24 lines (23 loc) · 1.06 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
# Supply-chain hardening directives (SC-12282 / LTS-3294)
# See: https://browserstack.atlassian.net/wiki/spaces/ENG/pages/6091571922/Supply+Chain+Security+Enhancements+Tech+Spec
#
# access=restricted is intentionally OMITTED — this is a public, customer-facing
# sample repository, not a published private package.
#
# ignore-scripts=true is now safe: browserstack-node-sdk is pinned directly in
# package.json to 1.60.1 — the version the Playwright BLU runner enforces in prod
# (docker-selenium/Playwright/download-test.js SDK_VERSION on lts-main) — so the old
# `postinstall: npm update browserstack-node-sdk` (the only install-script this
# sample needed) has been removed.
#
# engine-strict=true enforces the package.json `engines.node` floor (>=18), which
# matches the Node version in our runner pod and what Playwright + the SDK already
# require. Customers on EOL Node (<18) get a clear upgrade message instead of an
# obscure runtime failure.
strict-ssl=true
save-exact=true
audit-level=high
legacy-peer-deps=false
ignore-scripts=true
engine-strict=true
min-release-age=7