Skip to content

Commit 98a905b

Browse files
committed
chore: fix after sonar
Security Hotspots Reviewed
1 parent 442aea9 commit 98a905b

1 file changed

Lines changed: 19 additions & 4 deletions

File tree

‎scripts/init.sh‎

Lines changed: 19 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -110,12 +110,27 @@ if [[ -f "tests-config.json" ]] && command -v node >/dev/null 2>&1; then
110110
'
111111
fi
112112

113-
# 5. npm install
113+
# 5. npm install — scripts disabled for supply-chain safety.
114+
# Lifecycle hooks of transitive deps are NOT executed.
115+
# We re-run only the hooks we explicitly trust below.
114116
if command -v npm >/dev/null 2>&1; then
115-
echo "[5/7] npm install"
116-
npm install --no-audit --no-fund
117+
echo "[5/7] npm install (scripts disabled)"
118+
npm install --no-audit --no-fund --ignore-scripts
119+
120+
# Re-run trusted lifecycle steps explicitly.
121+
# husky: needed to install git hooks from templates/husky/.
122+
if [ -d .git ] && [ -f node_modules/husky/bin.mjs ]; then
123+
echo "[5/7] husky init (explicit, replaces skipped postinstall)"
124+
npx --no-install husky || true
125+
fi
117126
else
118-
echo "[5/7] npm not found — install Node 20+ then run 'npm install' manually"
127+
echo "[5/7] npm not found — install Node 20+ then run 'npm install --ignore-scripts' manually"
128+
fi
129+
130+
# 6. playwright install — browsers (not the npm package)
131+
if command -v npx >/dev/null 2>&1; then
132+
echo "[6/7] playwright install (browsers)"
133+
npx --no-install playwright install --with-deps chromium
119134
fi
120135

121136
# 6. playwright install

0 commit comments

Comments
 (0)