87 packages matching “allowScripts”
npm-script-lens
v1.18.0 · 6 days ago
See what an install script actually does before you approve it: behavioral analysis, binding.gyp inspection and resolved provenance identity for npm 12 allowScripts, pnpm allowBuilds, yarn and bun
No known vulnerabilities
assurly
v1.2.2 · 2 months ago
Pre-deploy ship gate for AI-built SaaS. Audits npm 12 install-script trust (allowScripts), MCP agent config, Supabase RLS, Stripe webhooks and leaked keys — offline, from files you already have. No upload, no sign-up.
No known vulnerabilities
@assurly/scanner-core
v1.2.2 · 2 months ago
Offline static-analysis rules behind Assurly: npm 12 install-script trust (allowScripts), MCP agent config auditing, slopsquat detection, Supabase RLS, Stripe webhooks, leaked service keys. Runs in Node or the browser.
No known vulnerabilities
allow-scripts-bot
v0.1.0 · 2 months ago
Classify npm install/postinstall scripts as safe or suspicious and generate an npm v12 allowScripts config, with an optional PR.
No known vulnerabilities
puppeteer-core
v25.12.0 · 6 days ago
A high-level API to control headless Chrome over the DevTools Protocol
No known vulnerabilities
node
v22.23.3 · 6 days ago
node
No known vulnerabilities
puppeteer
v25.12.0 · 6 days ago
A high-level API to control headless Chrome over the DevTools Protocol
No known vulnerabilities
@wojciech_lesicki/security-testing-demo
v1.0.0 · 1 month ago
Test-only container package that depends on @wojciech_lesicki/security-lifecycle-demo, used to verify its behavior end-to-end as a real dependency (install, lifecycle scripts, allowScripts blocking) rather than as the root project.
No known vulnerabilities
@wojciech_lesicki/security-lifecycle-demo
v1.0.0 · 1 month ago
Educational demo of npm preinstall/postinstall lifecycle scripts - each hook fetches a package's registry metadata and logs the response, and reports how npm >=12's allowScripts blocking affects it.
No known vulnerabilities
@hypernewbie/phi-code
v0.21.5 · 1 day ago
Terminal multiplexer & control center for AI coding assistants
No known vulnerabilities
protoc-gen-js
v4.0.3 · 10 days ago
A protoc-gen-js binary for npm.
No known vulnerabilities
create-better-t-stack
v3.44.2 · 2 days ago
A modern CLI tool for scaffolding end-to-end type-safe TypeScript projects with best practices and customizable configurations
No known vulnerabilities
@rebasepro/server-postgres
v0.23.0 · 2 days ago
PostgreSQL data source backend implementation for Rebase with Drizzle ORM
No known vulnerabilities
@ivuorinen/browserslist-config
v1.3.25 · 22 hours ago
ivuorinen's shareable configuration for Browserslist.
No known vulnerabilities
node-version-use
v2.6.0 · 15 days ago
Cross-platform solution for using multiple versions of node. Useful for compatibility testing
No known vulnerabilities
@monoes/memory
v1.0.23 · 13 hours ago
Memory module - JSON pattern store and a SQLite + embeddings backend with a size-gated HNSW ANN fast path built in
No known vulnerabilities
rust-cargo-cli
v1.0.2 · 19 days ago
Rust toolchain as npm CLI package — automatically downloads rustup and installs cargo, rustc, rustup, rustfmt and rustdoc for the current platform
No known vulnerabilities
@ivuorinen/eslint-config
v2.0.1 · 6 hours ago
ivuorinen's shareable configuration for ESLint.
No known vulnerabilities
@monoes/hooks
v1.0.11 · 2 days ago
Hook type definitions, an in-memory HookRegistry/HookExecutor, and a WorkerManager with 8 on-demand background workers (health/ddd/security/cache/map/audit/consolidate/progress). Not the runtime hook dispatcher — the live path is .claude/helpers/ (CJS han
No known vulnerabilities
pi-worker
v0.12.1 · 3 days ago
Run exact Pi models as bounded workers for coding agents.
No known vulnerabilities