fix(config): avoid exporting persistent allow-scripts - #9913
Conversation
| default: '', | ||
| type: [String, Array], | ||
| hint: '<package-list>', | ||
| envExport: false, |
There was a problem hiding this comment.
Thanks for the fix. Marking allow-scripts as envExport: false is the right shared solution: it prevents Config.load() / setEnvs() from turning file-backed policy into an environment-layer override before either npm run or Pacote Git preparation starts a child process. This addresses #9912 and actually fixes the persistent- .npmrc case in #9783 .
There was a problem hiding this comment.
@Fnine59 Setting envExport: false causes Definition.describe() to append the non-export notice. test/lib/docs.js snapshots every generated config description, but the committed docs.js.test.cjs snapshot still lacks that notice for allow-scripts. Regenerate and commit tap-snapshots/test/lib/docs.js.test.cjs
TAP_SNAPSHOT=1 node test/lib/docs.js
There was a problem hiding this comment.
Updated in c06d865: regenerated and committed the config description snapshot. Verified node test/lib/docs.js passes on Node 24.15.0 (6/6).
What / Why
A user or global
.npmrccan defineallow-scriptsas persistent policy.setEnvs()currently carries that non-default value into lifecycle child processes asnpm_config_allow_scripts. If a lifecycle script runs a nested project-scopednpm install, the inner process treats the inherited value as an environment override and rejects it withEALLOWSCRIPTSinstead of reloading the policy from its persistent config source.Mark
allow-scriptsas non-exportable. This only preventssetEnvs()from synthesizing the lifecycle environment variable; it does not remove an explicitly supplied environment value or change how the outer command reads its config. Pacote's git-preparation environment filtering and #9783 are outside this change.The regression test models a user-level value in the inherited config chain and verifies that lifecycle scripts do not receive
npm_config_allow_scripts.AI assistance
OpenAI Codex assisted with analysis, implementation, and test design. The patch was verified with the focused regression, the complete
@npmcli/configsuite, lint, and template checks.References
Fixes #9912