Skip to content

fix(config): avoid exporting persistent allow-scripts - #9937

Open
github-actions[bot] wants to merge 1 commit into
release/v11from
backport/v11/9913
Open

fix(config): avoid exporting persistent allow-scripts#9937
github-actions[bot] wants to merge 1 commit into
release/v11from
backport/v11/9913

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Backport of #9913 to release/v11.

## What / Why

A user or global `.npmrc` can define `allow-scripts` as persistent
policy. `setEnvs()` currently carries that non-default value into
lifecycle child processes as `npm_config_allow_scripts`. If a lifecycle
script runs a nested project-scoped `npm install`, the inner process
treats the inherited value as an environment override and rejects it
with `EALLOWSCRIPTS` instead of reloading the policy from its persistent
config source.

Mark `allow-scripts` as non-exportable. This only prevents `setEnvs()`
from synthesizing the lifecycle environment variable; it does not remove
an explicitly supplied environment value or change how the outer command
reads its config. Pacote's git-preparation environment filtering and
#9783 are outside this change.

The regression test models a user-level value in the inherited config
chain and verifies that lifecycle scripts do not receive
`npm_config_allow_scripts`.

## AI assistance

OpenAI Codex assisted with analysis, implementation, and test design.
The patch was verified with the focused regression, the complete
`@npmcli/config` suite, lint, and template checks.

## References

Fixes #9912

(cherry picked from commit b016aa2)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant