Skip to content

Avoid npx when running build and test tooling #2654

Description

@westonruter

See Core-65864:

npx downloads a package and its dependencies from the registry when it cannot find that package locally, then runs the install scripts of every one of them.
Each call is a point where a compromised package can run code during a build.
...
Replace each call with npm exec --no, which runs an installed binary and fails when the package is missing.

There are just a few such instances: https://github.com/search?q=repo%3AWordPress%2Fperformance+npx&type=code

See WordPress/wordpress-develop#13021

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    InfrastructureIssues for the overall performance plugin infrastructure[Type] EnhancementA suggestion for improvement of an existing feature

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions