Skip to content

chore: refresh README/SECURITY.md and harden npm install-script policy - #360

Merged
ggainey merged 5 commits into
pulp:mainfrom
Redtigercod4:chore/docs-and-tooling-refresh
Sep 14, 2026
Merged

chore: refresh README/SECURITY.md and harden npm install-script policy#360
ggainey merged 5 commits into
pulp:mainfrom
Redtigercod4:chore/docs-and-tooling-refresh

Conversation

@Redtigercod4

@Redtigercod4 Redtigercod4 commented Sep 13, 2026

Copy link
Copy Markdown
Contributor

Summary

Refreshed documentation relevant to the development and overview of PulpUI, this now includes the governance documentation needed on this repository aligned to the Pulp organisation. This update does also address all known npm audit vulnerabilities with package updates to webpack. Finally, it also includes a hardened .npmrc file to mitigate potential attack vectors recently found in Shai-Hulud type attacks.

Changes

  1. Refreshed README.md with better guidance and overview of the application.
  2. Added SECURITY.md aligned to the new Pulp Governance requirements at the organisation level.
  3. Hardened .npmrc configuration with best practices to mitigate any Shai-Hulud or wider attacks.
  4. Bumped associated packages to address all vulnerabilities highlighted in npm audit.

Out of Scope

  1. Documentation changes to Pulp Docs related to PulpUI

Blockers

N/A

Linked issue

N/A

Sources

  1. https://github.com/pulp/governance
  2. https://snyk.io/articles/npm-security-best-practices-shai-hulud-attack/

@Redtigercod4 Redtigercod4 changed the title chore: refreshed documentation and tooling with all known package vulnerabilities addressed. chore: refreshed documentation and tooling with all known package vulnerabilities addressed Sep 13, 2026
@Redtigercod4 Redtigercod4 changed the title chore: refreshed documentation and tooling with all known package vulnerabilities addressed chore: refresh README/SECURITY.md and harden npm install-script policy Sep 13, 2026
@Redtigercod4
Redtigercod4 force-pushed the chore/docs-and-tooling-refresh branch 2 times, most recently from 8179a07 to c85ba1e Compare September 14, 2026 11:57
@Redtigercod4
Redtigercod4 force-pushed the chore/docs-and-tooling-refresh branch from 8da4973 to ef0d507 Compare September 14, 2026 12:04
@Redtigercod4
Redtigercod4 force-pushed the chore/docs-and-tooling-refresh branch from ef0d507 to 5091a18 Compare September 14, 2026 12:06
@Redtigercod4
Redtigercod4 marked this pull request as ready for review September 14, 2026 12:41

@ggainey ggainey left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The docs-updates are especially welcome - thank you for thorough work here.

@ggainey
ggainey merged commit 90c94bf into pulp:main Sep 14, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants