Skip to content

chore: deny unreviewed dependency install scripts - #21

Merged
clappingmonkey merged 1 commit into
mainfrom
chore/deny-install-scripts
Sep 26, 2026
Merged

clappingmonkey merged 1 commit into
mainfrom
chore/deny-install-scripts

Conversation

@clappingmonkey

@clappingmonkey clappingmonkey commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

What & why

npm 11 warns on every npm ci that msgpackr-extract has an install script nobody has reviewed. It comes in via @opencode-ai/plugin → effect → msgpackr.

  • package.json: adds allowScripts: { "msgpackr-extract": false }. It's an optional native speedup: msgpackr falls back to pure JS, and we only import types from the plugin package.
  • .npmrc: adds strict-allow-scripts=true, so a new unreviewed install script fails npm ci instead of only warning. npm 12 will block these by default.

Consumers are unaffected. allowScripts is only read from the root project, and .npmrc is never packed. Renovate runs npm with scripts disabled, so it can still open PRs. CI on a PR that adds a new install-script dependency will fail until the script is approved or denied with npm install-scripts approve|deny <pkg>.

Closes: N/A (audit item C7)

Behavior impact

  • Theme-switching logic (periodFor, boundaries, gentle override)
  • Plugin options (dayTheme, nightTheme, dayStartHour, nightStartHour,
    checkIntervalMs, toast) — README options table updated
  • Lifecycle / timer / toast behavior
  • Packaging (package.json exports, files, published contents)
  • No user-facing behavior change

Testing

  • npm run typecheck passes
  • npm test passes (22/22)
  • Manually verified in opencode (if behavior changed): not applicable, no behavior change

Also verified:

  • npm ci no longer prints the install-scripts warning. With the deny entry removed, it fails with --strict-allow-scripts, as intended.
  • npm pack --dry-run lists only LICENSE, README.md, package.json and src/index.ts.

Checklist

  • PR title follows Conventional Commits
    (enforced by the PR Title check; drives the release-please version bump)
  • Defaults still work with zero config
  • Docs updated if behavior/config changed (no behavior/config change)
  • No secrets or credentials introduced

- deny msgpackr-extract (optional native speedup; only types are used from @opencode-ai/plugin)
- .npmrc strict-allow-scripts=true so any new unreviewed install script fails npm ci
@clappingmonkey
clappingmonkey merged commit 6edb7a3 into main Sep 26, 2026
4 checks passed
@clappingmonkey
clappingmonkey deleted the chore/deny-install-scripts branch September 26, 2026 10:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant