You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
browserstack.json's npm_dependencies were merged into a temp package.json and
installed with `npm install` and no `--ignore-scripts`, so a PR-supplied malicious
package's lifecycle script (postinstall) executed on CI (RCE, credential theft).
- Add `--ignore-scripts` to both npm install invocations (the RCE fix). npm_dependencies
is documented pure-JS only.
- Validate each dependency name (standard npm package-name regex) and version
(semver/dist-tag charset only) before writing package.json, rejecting git-url / file: /
path / alternate-registry specs (dependency confusion / code-exec via spec).
- shell:true is retained deliberately: the command line is fully static (names live in
package.json data, never on the command line -> no injection surface) and it is
required for the output redirection and for invoking npm.cmd on Windows.
Tested: validation rejects shell-metachar/git-url/file/$() specs, accepts normal semver;
--ignore-scripts present in both installs; syntax clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
0 commit comments