Skip to content

chore: add security hardening#176

Merged
nikosxenakis merged 1 commit intomainfrom
nikosxenakis/SDK-2664-security-hardening
Apr 14, 2026
Merged

chore: add security hardening#176
nikosxenakis merged 1 commit intomainfrom
nikosxenakis/SDK-2664-security-hardening

Conversation

@nikosxenakis
Copy link
Copy Markdown
Contributor

Summary

  • Add SECURITY.md with DFINITY's vulnerability reporting policy and bug bounty program details
  • Add ignore-scripts=true to .npmrc to prevent lifecycle scripts from running during install (supply-chain attack mitigation)

Context

Part of SDK-2664 security hardening across JS/TS repos.

Note: minimumReleaseAge is not included as this is an npm project and the setting is pnpm-specific.

@nikosxenakis nikosxenakis requested a review from a team as a code owner April 14, 2026 13:47
@nikosxenakis nikosxenakis merged commit 55d5e4d into main Apr 14, 2026
23 checks passed
@nikosxenakis nikosxenakis deleted the nikosxenakis/SDK-2664-security-hardening branch April 14, 2026 14:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants