Skip to content

Conversation

@rensvmoorsel
Copy link
Contributor

No description provided.

@SilasPeters
Copy link
Member

Other places might also download node packages, like the systemd service for backup-to-s3

@SilasPeters
Copy link
Member

SilasPeters commented Sep 30, 2025

What needs to be done before we merge:

  • Replace all npm install with npm ci --no-scripts
  • Secure all other places where node is used (npx, npm exec, others?)
  • Secure dockerfiles for images used on sadserver (thus possibly requiring changes in other repositories)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants