Security: Opt in to the npm v12 supply-chain defaults - #82689
manzoorwanijk wants to merge 2 commits into
Conversation
Now that CI and contributors are on Node 24 with npm v11 (5715a61), the repository can adopt the hardening that npm v12 turns on by default. Dependencies must resolve from the registry: git references, tarball URLs and local tarball files are refused outright, since nothing in the tree uses them. Directory dependencies stay allowed for the root and workspace package.json files, which the 1121 `file:` workspace links need, but a transitive dependency can no longer pull one in. Install scripts are denied by default. Every dependency that ships one is listed as `false` in the allowScripts policy, and strict-allow-scripts makes anything missing from that list a failed install rather than a warning. Nothing here needs its install script: build, typecheck, lint and unit tests all pass with them skipped. Both policies surface as an install failure rather than a warning, so the contributor workflow for each is documented alongside them. This revives #79614, which had to be reverted in #79667 because CI still ran an npm that predated these features.
🤖 PR meta 🤖📦 Bundle sizeSize Change: 0 B Total Size: 8.07 MB
⚡ PerformanceShow the resultsClient side metrics exclude the server response time. front-end-block-theme
front-end-classic-theme
media-processing
media-upload
post-editor
site-editor
🏁 Flaky testsShow the failuresSome tests passed with failed attempts. The failures may not be related to this commit but are still reported for visibility. See the documentation for more information. As a site builder, I want to insert a core navigation overlay pattern with CTA and see it on the frontend (Site Editor v2) in
|
|
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message. To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
| strict-allow-scripts = true | ||
| # only allow dependencies resolved from the registry | ||
| allow-git = none | ||
| allow-remote = none |
There was a problem hiding this comment.
Won't this break npm ci for people who use a registry mirror (Artifactory, Nexus, a company proxy)? On npm 11, npm compares the tarball host from the lockfile with the registry host, and it does not apply replace-registry-host first. The lockfile always points to registry.npmjs.org, so those installs fail with EALLOWREMOTE and there is no way around it.
npm 12 fixes the comparison. Maybe we should land this after #82328?
There was a problem hiding this comment.
It won't if you use the latest v11 (>=11.18). I fixed that bug in npm in npm/cli#9550
| "@swc/core": false, | ||
| "core-js": false, | ||
| "core-js-pure": false, | ||
| "esbuild": false, |
There was a problem hiding this comment.
On npm 11, denying an install script also skips bin linking, so node_modules/.bin/esbuild and node_modules/.bin/nx won't be created.
Our builds are fine because we import esbuild as a JS API, but npm exec --no -- esbuild stops working, and AGENTS.md tells contributors to use exactly that.
I believe that is also fixed in npm 12.
There was a problem hiding this comment.
This is also fixed in the latest version via npm/cli#9686
| Install scripts are denied by default: every dependency that ships one is listed in `allowScripts` in the root `package.json`, and anything missing from that list fails the install with `ESTRICTALLOWSCRIPTS`. When that happens, read the script, then record the decision and commit the `package.json` change: | ||
|
|
||
| ```bash | ||
| npm install-scripts deny <pkg> # the package works without its install script |
There was a problem hiding this comment.
npm install-scripts only exists in npm 12. On npm 11 it fails with Unknown command. npm 11 uses npm approve-scripts and npm deny-scripts instead. Maybe we should mention both, or say that this needs npm 12?
There was a problem hiding this comment.
It's updated in npm >= 11.18 after npm/cli#9629
|
Do you all think that this should be done via #82328 - npm 12 upgrade instead? |
I wouldn't be opposed, but I honestly missed the fact that all of these were fixed in v11. It really depends on when v12 lands - if it takes a while, maybe it's worth doing these now while we're on v11. |
|
We could move gradually and merge this PR, and later update to npm 12? |
|
My only concern is that the project's required minimum npm version has bugs, as @tyxla reported above. Should we expect the contributors to have the latest npm version regardless of what is required? |
|
Mhh, that's a good counterpoint. Realistically, can we "afford" to wait longer and switch to npm 12 directly? If so, then maybe that's a better choice |
|
Yes, I think it is better to push for #82328 to have npm v12 available ASAP. |
|
Closing in favor of #82732 |
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts. npm v12 keys `pack --json` output by package name rather than returning an array, so the two pack helpers read both shapes. Create Block opts out of the setup-node npm cache, which calls `npm config get cache` under the bundled npm and fails the devEngines check. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts. npm v12 keys `pack --json` output by package name rather than returning an array, so the two pack helpers read both shapes. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts. npm v12 keys `pack --json` output by package name rather than returning an array, so the two pack helpers read both shapes. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts. npm v12 keys `pack --json` output by package name rather than returning an array, so the two pack helpers read both shapes. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts. npm v12 keys `pack --json` output by package name rather than returning an array, so the two pack helpers read both shapes. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts. npm v12 keys `pack --json` output by package name rather than returning an array, so the two pack helpers read both shapes. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts. npm v12 keys `pack --json` output by package name rather than returning an array, so the two pack helpers read both shapes. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts. npm v12 keys `pack --json` output by package name rather than returning an array, so the two pack helpers read both shapes. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts. npm v12 keys `pack --json` output by package name rather than returning an array, so the two pack helpers read both shapes. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts. npm v12 keys `pack --json` output by package name rather than returning an array, so the two pack helpers read both shapes. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts. npm v12 keys `pack --json` output by package name rather than returning an array, so the two pack helpers read both shapes. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts. npm v12 keys `pack --json` output by package name rather than returning an array, so the two pack helpers read both shapes. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts. npm v12 keys `pack --json` output by package name rather than returning an array, so the two pack helpers read both shapes. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts. npm v12 keys `pack --json` output by package name rather than returning an array, so the two pack helpers read both shapes. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts. npm v12 keys `pack --json` output by package name rather than returning an array, so the two pack helpers read both shapes. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts. npm v12 keys `pack --json` output by package name rather than returning an array, so the two pack helpers read both shapes. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts. npm v12 keys `pack --json` output by package name rather than returning an array, so the two pack helpers read both shapes. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts. npm v12 keys `pack --json` output by package name rather than returning an array, so the two pack helpers read both shapes. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts. npm v12 keys `pack --json` output by package name rather than returning an array, so the two pack helpers read both shapes. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts, all denied: nothing compiles on install. npm 12 does not exempt workspace lifecycle scripts from allowScripts under install-strategy=linked, so @wordpress/icons needs an entry of its own to keep generating src/library on install. See npm/cli#9982. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts, all denied: nothing compiles on install. npm 12 does not exempt workspace lifecycle scripts from allowScripts under install-strategy=linked, so @wordpress/icons needs an entry of its own to keep generating src/library on install. See npm/cli#9982. Closes #82328. Supersedes #82689.
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts, all denied: nothing compiles on install. npm 12 does not exempt workspace lifecycle scripts from allowScripts under install-strategy=linked, so @wordpress/icons needs an entry of its own to keep generating src/library on install. See npm/cli#9982. Closes #82328. Supersedes #82689.
What?
Closes #74877. Follow up to #82370. Opts in to the npm supply chain protections that become the default in npm v12.
Partial and temporary: #82328 tracks installing npm 12, after which these become defaults.
Why?
Revives #79614, reverted in #79667.
How?
.npmrcrefuses git references, tarball URLs and local tarballs, and limits directory dependencies to those the root or a workspace declares.allowScriptsdenies all ten dependencies that ship an install script, andstrict-allow-scriptsfails the install on anything absent from that list. #74877 proposedignore-scripts, which would also disable our own scripts; this blocks dependencies only.Testing Instructions
node_modules, thennpm ci.package-lock.jsonshould be unchanged.npm run build,npm run typecheckandnpm run lint:jsshould pass.package.json):npm install --dry-run --no-save github:sindresorhus/is-odd npm install --dry-run --no-save https://registry.npmjs.org/is-odd/-/is-odd-3.0.1.tgz npm pkg delete allowScripts.esbuild && npm install --dry-run git checkout package.jsonnpm init -y && npm link, then from the repo:Testing Instructions for Keyboard
N/A, no user interface change.
Use of AI Tools
Claude Code researched the npm settings and verified them against clean installs. I reviewed all changes.
🤖 Generated with Claude Code