angular / angular/angular-cli

Manually execute `ng new` deps postinstall scripts

未关闭
#22,013 3 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
area: @schematics/angular feature feature: insufficient votes severity6: security
主要语言
TypeScript
星标
27k
派生
11.8k
平均合并
14 小时 23 分钟
30 天内合并 PR
162

描述

# 🚀 Feature request

### Command (mark with an `x`)

- [X] new

### Description

Currently, `ng new` will automatically run `npm install` which (if the user has not disabled it), automatically runs all postinstall scripts. This can be a vulnerability since any compromised package in the NPM dependency graph could add a postinstall step to install malware on developer machines.

### Describe the solution you'd like

We could reduce the attack surface by disabling postinstall on the automatic `npm install` and then manually invoke the postinstall for a known set of required packages. Only 3 packages currently use postinstall steps, so limiting execution to just those would significantly reduce the attack surface for a potential supply chain attack.

One possible concern is for dependencies which add a required postinstall step in the future. We can pretty easily add a test to make sure we aren't missing any postinstall steps from our transitive dependencies, though this inherently breaks abstraction somewhat. Adding a postinstall step is (somewhat debate-ably) a breaking change, so any package which adds one in the future should require a major version bump where we have an opportunity to allowlist it.

The one edge case I can think of is if we have:

```
ng-new-app@0.0.0 -> package-a@^1.0.0 -> package-b@^1.0.0
```

And `package-b` gets a new postinstall step in `v2.0.0`. However, `package-a` may be able to manage the breakage without violating their own public API (or maybe doesn't notice the new postinstall step) and simply bumps to `v1.0.1`. This would immediately be pulled in to the next `ng new` command and fail. I think such a scenario would actually be a bad patch release for `package-a`, since adding a required postinstall step is fundamentally a breaking change. We would rely on NPM package maintainers to make the right semver-compatible decisions for a somewhat nuanced case, but this is probably better than the alternative.

贡献指南

打开贡献指南

调研方向

首先检查会自动运行 npm install 的 ng new 流程,并确定当前如何处理 postinstall 脚本。完成标准是禁用广泛的自动 postinstall 执行,仅调用所需的已知包,并添加用于检测缺失 postinstall 依赖的覆盖测试。

由索引模型根据 Issue 内容生成。

评估

技术栈
typescript
领域
cli, security
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
停滞
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。