[wp-trac] [WordPress Trac] #64543: Implement `ignore-scripts` to harden npm usage

WordPress Trac noreply at wordpress.org
Fri Jan 23 09:58:02 UTC 2026


#64543: Implement `ignore-scripts` to harden npm usage
------------------------------+------------------------------
 Reporter:  johnbillion       |       Owner:  (none)
     Type:  task (blessed)    |      Status:  new
 Priority:  normal            |   Milestone:  Awaiting Review
Component:  Build/Test Tools  |     Version:
 Severity:  normal            |  Resolution:
 Keywords:                    |     Focuses:
------------------------------+------------------------------

Comment (by jonsurrell):

 [https://github.com/WordPress/gutenberg/pull/74689 The proposed switch to
 pnpm is interesting in this regard.] [https://pnpm.io/config-dependencies
 #loading-an-allow-list-of-built-dependencies It can be configured to allow
 certain dependencies to be built.]

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/64543#comment:1>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list