|
|
|
|
|
by fragmede
236 days ago
|
|
Am I missing something? Don't you also need to change how CI and deployment processes call npm? If my CI server and then also my deployment scripts are calling npm the old insecure way, and running infected install scripts/whatever, haven't I just still fucked myself, just on my CI server and whatever deployment system(s) are involved? That seems bad. |
|
Further, you are welcome to use this alias on your CI as well to enhance the protection.