-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy path.npmrc
More file actions
25 lines (24 loc) · 1.2 KB
/
Copy path.npmrc
File metadata and controls
25 lines (24 loc) · 1.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
# Supply-chain hardening directives (SC-12282 / LTS-3295)
# See: https://browserstack.atlassian.net/wiki/spaces/ENG/pages/6091571922/Supply+Chain+Security+Enhancements+Tech+Spec
#
# access=restricted is intentionally OMITTED — this is a public, customer-facing
# sample repository, not a published private package.
#
# ignore-scripts=true is now safe: these tests run remotely on BrowserStack, and
# Edge/Gecko are not supported on our platform, so the local driver-binary
# postinstalls (edgedriver/geckodriver) are not needed. browserstack-node-sdk is
# pinned to the latest release (1.61.0) so no update-postinstall is needed either.
#
# engine-strict=true enforces the package.json `engines.node` floor (>=22.12.0).
# The floor was raised from >=18 for LTS-4750: the only fix for the unpatched
# extract-zip path traversal (GHSA-jmr9-qjv8-65gv) is @puppeteer/browsers 3.x,
# which is ESM-only and requires Node >=22.12.0. Node 18 (EOL 2025-04-30) and
# Node 20 (EOL 2026-04-30) are both out of support anyway, so customers on EOL
# Node get a clear upgrade message instead of obscure failures.
strict-ssl=true
save-exact=true
audit-level=high
legacy-peer-deps=false
ignore-scripts=true
engine-strict=true
min-release-age=7