Skip to content

Conversation

@labkey-tchad
Copy link
Member

Rationale

By requiring all NPM dependencies to come from registry.npmjs.org or labkey.jfrog.io, we can reduce the risk of downloading malicious code.

Related Pull Requests

  • N/A

Changes

  • Add test to check package-lock.json files for suspicious dependencies

@labkey-tchad labkey-tchad added this to the 26.02 milestone Jan 28, 2026
Copy link
Contributor

@labkey-alan labkey-alan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me.

@labkey-tchad labkey-tchad merged commit 71642ca into develop Jan 29, 2026
5 checks passed
@labkey-tchad labkey-tchad deleted the fb_packageLockTest branch January 29, 2026 21:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants