All skills
secondsky avatar

/dependency-upgrade

@9816df2
by Eddiesecondsky/sap-skills456 stars
120

Secure dependency upgrades with supply chain protection, cooldowns, and staged rollout. Use when upgrading deps, configuring security policies, or preventing supply chain attacks.

Use this Skill: https://skilld.dev/gh/secondsky/sap-skills/dependency-upgrade

This session only. Nothing lands on disk.

referencespackage-manager-security.md

≈1.3k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Package Manager Security Hardening

Per-package-manager security configuration covering post-install scripts, deterministic installs, and supply chain protections.

npm

Disable Lifecycle Scripts

# .npmrc
ignore-scripts=true
allow-git=none
# Global
npm config set ignore-scripts true
npm config set allow-git none

--allow-git=none (npm CLI 11.10.0+) prevents git-based dependencies from shipping .npmrc files that re-enable lifecycle scripts, closing a bypass vector.

Deterministic Installs

# CI/CD — strict lockfile adherence
npm ci
npm ci --only=production

# Never use npm install in CI

npm ci:

  • Deletes node_modules before installing
  • Requires package-lock.json to exist
  • Fails if lockfile is out of sync with package.json
  • Installs exact versions from lockfile only

Lockfile Validation

npm install --save-dev lockfile-lint

npx lockfile-lint \
  --path package-lock.json \
  --type npm \
  --allowed-hosts npm yarn \
  --validate-https

Cooldown

# .npmrc
min-release-age=7

Bun

Post-Install Script Control

Bun disables postinstall scripts by default. Allow specific packages via package.json:

{
  "trustedDependencies": [
    "esbuild",
    "sharp"
  ]
}

Deterministic Installs

# Frozen lockfile mode (CI)
bun install --frozen-lockfile

Cooldown

# bunfig.toml
[install]
minimumReleaseAge = 604800  # 7 days in seconds
minimumReleaseAgeExcludes = ["@types/bun", "typescript"]

Lockfile Notes

Bun uses bun.lock (text, default since v1.2) or bun.lockb (binary). lockfile-lint does not support Bun lockfile formats currently.

pnpm

Post-Install Script Control (10.0+)

pnpm disables postinstall scripts by default since v10.0.

# pnpm-workspace.yaml

# Preferred (pnpm 10.26+)
allowBuilds:
  esbuild: true
  fsevents: true
  nx@21.6.4 || 21.6.5: true
  core-js: false

# Legacy (still supported)
# onlyBuiltDependencies:
#   - esbuild
#   - fsevents

# Hard error on unreviewed scripts (pnpm 10.3+)
strictDepBuilds: true

Trust Policy (pnpm 10.21+)

Detect when a package's trust level has decreased — early signal of account compromise:

# pnpm-workspace.yaml
trustPolicy: no-downgrade

trustPolicyExclude:
  - 'chokidar@4.0.3'
  - 'webpack@4.47.0 || 5.102.1'

# Ignore packages published >30 days ago (pnpm 10.27+)
trustPolicyIgnoreAfter: 43200  # minutes

Trust levels (strongest → weakest):

  1. Trusted Publisher (OIDC/GitHub Actions)
  2. Provenance (npm provenance attestation)
  3. Signatures (registry signature)
  4. No evidence

Block Exotic Transitive Dependencies (pnpm 10.26+)

# pnpm-workspace.yaml
blockExoticSubdeps: true

Prevents transitive dependencies from using git repos or direct tarball URLs. Only direct dependencies in package.json may use exotic sources.

Deterministic Installs

# Frozen lockfile (CI)
pnpm install --frozen-lockfile

Lockfile Security

pnpm is inherently more resistant to lockfile injection:

  • Doesn't maintain modifiable tarball sources
  • Won't install lockfile packages not declared in package.json
  • pnpm-lock.yaml format is more resistant to injection

Cooldown

# pnpm-workspace.yaml
minimumReleaseAge: 10080  # 7 days in minutes
minimumReleaseAgeExclude:
  - '@types/react'
  - typescript

Yarn

Deterministic Installs

# Validate lockfile did not mutate
yarn install --immutable --immutable-cache

Cooldown (Yarn 4.10+)

# .yarnrc.yml
npmMinimalAgeGate: "7d"
npmPreapprovedPackages:
  - "@types/react"
  - "typescript"

Lockfile Validation

npx lockfile-lint \
  --path yarn.lock \
  --type yarn \
  --allowed-hosts npm yarn \
  --validate-https

Deno

Deterministic Installs

deno install --frozen

Lockfile

Deno uses deno.lock. Ensure it's committed to version control.

Cross-PM Cheat Sheet

Feature npm Bun pnpm Yarn Deno
Disable scripts ignore-scripts=true Default off Default off (10.0+) N/A N/A
Script allowlist @lavamoat/allow-scripts trustedDependencies allowBuilds N/A N/A
Frozen install npm ci --frozen-lockfile --frozen-lockfile --immutable --frozen
Cooldown min-release-age minimumReleaseAge (sec) minimumReleaseAge (min) npmMinimalAgeGate N/A
Lockfile format package-lock.json bun.lock / bun.lockb pnpm-lock.yaml yarn.lock deno.lock
Lockfile lint lockfile-lint Not supported lockfile-lint lockfile-lint N/A
Trust policy N/A N/A trustPolicy (10.21+) N/A N/A
Block exotic deps N/A N/A blockExoticSubdeps (10.26+) N/A N/A
Lockfile to commit package-lock.json bun.lock pnpm-lock.yaml yarn.lock deno.lock

Committing Lockfiles

Always commit lockfiles to version control:

git add package-lock.json      # npm
git add bun.lock                # Bun
git add pnpm-lock.yaml          # pnpm
git add yarn.lock               # Yarn
git add deno.lock               # Deno

Never add lockfiles to .gitignore. They are the source of truth for reproducible installs.

Source: SKILL.md on GitHub

No alerts3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    This skill provides comprehensive, security-focused guidance and templates for managing dependency upgrades in JavaScript, Node.js, and multi-language projects. It implements best practices for supply chain protection, including dependency cooldown periods, lifecycle script blocking, and lockfile validation using industry-standard tools like Socket, npq, and lockfile-lint.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: LOW · No issues

Signed by skilld at 9816df2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 4 months ago

README badge

README badge for secondsky/sap-skills/dependency-upgrade