Skip to content

fix(config): avoid exporting persistent allow-scripts - #9913

Open
Fnine59 wants to merge 1 commit into
npm:latestfrom
Fnine59:fix/npm-allow-scripts-env-9912
Open

fix(config): avoid exporting persistent allow-scripts#9913
Fnine59 wants to merge 1 commit into
npm:latestfrom
Fnine59:fix/npm-allow-scripts-env-9912

Conversation

@Fnine59

@Fnine59 Fnine59 commented Aug 24, 2026

Copy link
Copy Markdown

What / Why

A user or global .npmrc can define allow-scripts as persistent policy. setEnvs() currently carries that non-default value into lifecycle child processes as npm_config_allow_scripts. If a lifecycle script runs a nested project-scoped npm install, the inner process treats the inherited value as an environment override and rejects it with EALLOWSCRIPTS instead of reloading the policy from its persistent config source.

Mark allow-scripts as non-exportable. This only prevents setEnvs() from synthesizing the lifecycle environment variable; it does not remove an explicitly supplied environment value or change how the outer command reads its config. Pacote's git-preparation environment filtering and #9783 are outside this change.

The regression test models a user-level value in the inherited config chain and verifies that lifecycle scripts do not receive npm_config_allow_scripts.

AI assistance

OpenAI Codex assisted with analysis, implementation, and test design. The patch was verified with the focused regression, the complete @npmcli/config suite, lint, and template checks.

References

Fixes #9912

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] A user/local .npmrc allow-scripts setting is forwarded to an inner npm install spawned by npm run-script and fails with EALLOWSCRIPTS

1 participant