304 lines
9.1 KiB
HTML
304 lines
9.1 KiB
HTML
<!DOCTYPE html><html><head>
|
|
<meta charset="utf-8">
|
|
<title>npm-approve-scripts</title>
|
|
<style>
|
|
body {
|
|
background-color: #ffffff;
|
|
color: #24292e;
|
|
|
|
margin: 0;
|
|
|
|
line-height: 1.5;
|
|
|
|
font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Helvetica, Arial, sans-serif, "Apple Color Emoji", "Segoe UI Emoji";
|
|
}
|
|
#rainbar {
|
|
height: 10px;
|
|
background-image: linear-gradient(139deg, #fb8817, #ff4b01, #c12127, #e02aff);
|
|
}
|
|
|
|
a {
|
|
text-decoration: none;
|
|
color: #0366d6;
|
|
}
|
|
a:hover {
|
|
text-decoration: underline;
|
|
}
|
|
|
|
pre {
|
|
margin: 1em 0px;
|
|
padding: 1em;
|
|
border: solid 1px #e1e4e8;
|
|
border-radius: 6px;
|
|
|
|
display: block;
|
|
overflow: auto;
|
|
|
|
white-space: pre;
|
|
|
|
background-color: #f6f8fa;
|
|
color: #393a34;
|
|
}
|
|
code {
|
|
font-family: SFMono-Regular, Consolas, "Liberation Mono", Menlo, Courier, monospace;
|
|
font-size: 85%;
|
|
padding: 0.2em 0.4em;
|
|
background-color: #f6f8fa;
|
|
color: #393a34;
|
|
}
|
|
pre > code {
|
|
padding: 0;
|
|
background-color: inherit;
|
|
color: inherit;
|
|
}
|
|
h1, h2, h3 {
|
|
font-weight: 600;
|
|
}
|
|
|
|
#logobar {
|
|
background-color: #333333;
|
|
margin: 0 auto;
|
|
padding: 1em 4em;
|
|
}
|
|
#logobar .logo {
|
|
float: left;
|
|
}
|
|
#logobar .title {
|
|
font-weight: 600;
|
|
color: #dddddd;
|
|
float: left;
|
|
margin: 5px 0 0 1em;
|
|
}
|
|
#logobar:after {
|
|
content: "";
|
|
display: block;
|
|
clear: both;
|
|
}
|
|
|
|
#content {
|
|
margin: 0 auto;
|
|
padding: 0 4em;
|
|
}
|
|
|
|
#table_of_contents > h2 {
|
|
font-size: 1.17em;
|
|
}
|
|
#table_of_contents ul:first-child {
|
|
border: solid 1px #e1e4e8;
|
|
border-radius: 6px;
|
|
padding: 1em;
|
|
background-color: #f6f8fa;
|
|
color: #393a34;
|
|
}
|
|
#table_of_contents ul {
|
|
list-style-type: none;
|
|
padding-left: 1.5em;
|
|
}
|
|
#table_of_contents li {
|
|
font-size: 0.9em;
|
|
}
|
|
#table_of_contents li a {
|
|
color: #000000;
|
|
}
|
|
|
|
header.title {
|
|
border-bottom: solid 1px #e1e4e8;
|
|
}
|
|
header.title > h1 {
|
|
margin-bottom: 0.25em;
|
|
}
|
|
header.title > .description {
|
|
display: block;
|
|
margin-bottom: 0.5em;
|
|
line-height: 1;
|
|
}
|
|
|
|
header.title .version {
|
|
font-size: 0.8em;
|
|
color: #666666;
|
|
}
|
|
|
|
footer#edit {
|
|
border-top: solid 1px #e1e4e8;
|
|
margin: 3em 0 4em 0;
|
|
padding-top: 2em;
|
|
}
|
|
|
|
table {
|
|
width: 100%;
|
|
margin: 1em 0;
|
|
border-radius: 6px;
|
|
border: 1px solid #e1e4e8;
|
|
overflow: hidden;
|
|
border-collapse: separate;
|
|
border-spacing: 0;
|
|
}
|
|
|
|
table thead {
|
|
background-color: #f6f8fa;
|
|
}
|
|
|
|
table tbody {
|
|
background-color: #ffffff;
|
|
}
|
|
|
|
table th,
|
|
table td {
|
|
padding: 0.75em;
|
|
text-align: left;
|
|
border-right: 1px solid #e1e4e8;
|
|
border-bottom: 1px solid #e1e4e8;
|
|
}
|
|
|
|
table th:last-child,
|
|
table td:last-child {
|
|
border-right: none;
|
|
}
|
|
|
|
table tbody tr:last-child td {
|
|
border-bottom: none;
|
|
}
|
|
|
|
table th {
|
|
font-weight: 600;
|
|
background-color: #f6f8fa;
|
|
}
|
|
|
|
table code {
|
|
white-space: nowrap;
|
|
}
|
|
|
|
</style>
|
|
</head>
|
|
<body>
|
|
<div id="banner">
|
|
<div id="rainbar"></div>
|
|
<div id="logobar">
|
|
<svg class="logo" role="img" height="32" width="32" viewBox="0 0 700 700">
|
|
<polygon fill="#cb0000" points="0,700 700,700 700,0 0,0"></polygon>
|
|
<polygon fill="#ffffff" points="150,550 350,550 350,250 450,250 450,550 550,550 550,150 150,150"></polygon>
|
|
</svg>
|
|
<div class="title">
|
|
npm command-line interface
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<section id="content">
|
|
<header class="title">
|
|
<h1 id="----npm-approve-scripts----11160">
|
|
<span>npm-approve-scripts</span>
|
|
<span class="version">@11.16.0</span>
|
|
</h1>
|
|
<span class="description">Approve install scripts for specific dependencies</span>
|
|
</header>
|
|
|
|
<section id="table_of_contents">
|
|
<h2 id="table-of-contents">Table of contents</h2>
|
|
<div id="_table_of_contents"><ul><li><a href="#synopsis">Synopsis</a></li><li><a href="#description">Description</a></li><li><a href="#examples">Examples</a></li><li><a href="#configuration">Configuration</a></li><ul><li><a href="#all"><code>all</code></a></li><li><a href="#allow-scripts-pending"><code>allow-scripts-pending</code></a></li><li><a href="#allow-scripts-pin"><code>allow-scripts-pin</code></a></li><li><a href="#json"><code>json</code></a></li></ul><li><a href="#see-also">See Also</a></li></ul></div>
|
|
</section>
|
|
|
|
<div id="_content"><h3 id="synopsis">Synopsis</h3>
|
|
<pre><code class="language-bash">npm approve-scripts <pkg> [<pkg> ...]
|
|
npm approve-scripts --all
|
|
npm approve-scripts --allow-scripts-pending
|
|
</code></pre>
|
|
<p>Note: This command is unaware of workspaces.</p>
|
|
<h3 id="description">Description</h3>
|
|
<p>Manages the <code>allowScripts</code> field in your project's <code>package.json</code>, which
|
|
records which of your dependencies are permitted to run install scripts
|
|
(<code>preinstall</code>, <code>install</code>, <code>postinstall</code>, and <code>prepare</code> for non-registry
|
|
sources). This command is the recommended way to maintain that field.</p>
|
|
<p>In the current release, this field is advisory: install scripts still run
|
|
by default, but installs print a list of packages whose scripts have not
|
|
been reviewed. A future release will block unreviewed install scripts.</p>
|
|
<p>There are three modes:</p>
|
|
<pre><code class="language-bash">npm approve-scripts <pkg> [<pkg> ...]
|
|
npm approve-scripts --all
|
|
npm approve-scripts --allow-scripts-pending
|
|
</code></pre>
|
|
<p><code><pkg></code> matches every installed version of that package. By default the
|
|
command writes pinned entries (<code>pkg@1.2.3</code>), which keep their approval
|
|
narrowed to the specific version you reviewed. Pass <code>--no-allow-scripts-pin</code> to write
|
|
name-only entries that allow any future version.</p>
|
|
<p><code>--all</code> approves every package with unreviewed install scripts in one go.</p>
|
|
<p><code>--allow-scripts-pending</code> is read-only: it lists every package whose install scripts
|
|
are not yet covered by <code>allowScripts</code>, without modifying <code>package.json</code>.</p>
|
|
<p><code>approve-scripts</code> honours the asymmetric pin rule: if you re-approve a
|
|
package whose installed version has changed, the existing pin is rewritten
|
|
to track the new installed version. Multi-version statements
|
|
(<code>pkg@1 || 2</code>) are left alone, since they likely capture intent that
|
|
the command cannot infer. Existing <code>false</code> entries always win;
|
|
<code>approve-scripts</code> will not silently re-allow a package you previously
|
|
denied.</p>
|
|
<h3 id="examples">Examples</h3>
|
|
<pre><code class="language-bash"># Approve all currently-installed install scripts after reviewing them
|
|
npm approve-scripts --all
|
|
|
|
# Approve specific packages, pinned to their installed version
|
|
npm approve-scripts canvas sharp
|
|
|
|
# Approve name-only (any version of this package is allowed)
|
|
npm approve-scripts --no-allow-scripts-pin canvas
|
|
|
|
# Preview which packages still need review
|
|
npm approve-scripts --allow-scripts-pending
|
|
</code></pre>
|
|
<h3 id="configuration">Configuration</h3>
|
|
<h4 id="all"><code>all</code></h4>
|
|
<ul>
|
|
<li>Default: false</li>
|
|
<li>Type: Boolean</li>
|
|
</ul>
|
|
<p>When running <code>npm outdated</code> and <code>npm ls</code>, setting <code>--all</code> will show all
|
|
outdated or installed packages, rather than only those directly depended
|
|
upon by the current project.</p>
|
|
<h4 id="allow-scripts-pending"><code>allow-scripts-pending</code></h4>
|
|
<ul>
|
|
<li>Default: false</li>
|
|
<li>Type: Boolean</li>
|
|
</ul>
|
|
<p>List packages with install scripts that are not yet covered by the
|
|
<code>allowScripts</code> policy, without modifying <code>package.json</code>. Only meaningful for
|
|
<code>npm approve-scripts</code>.</p>
|
|
<h4 id="allow-scripts-pin"><code>allow-scripts-pin</code></h4>
|
|
<ul>
|
|
<li>Default: true</li>
|
|
<li>Type: Boolean</li>
|
|
</ul>
|
|
<p>Write pinned (<code>pkg@version</code>) entries when approving install scripts. Set to
|
|
<code>false</code> to write name-only entries that allow any version. Has no effect on
|
|
<code>npm deny-scripts</code>, which always writes name-only entries regardless of this
|
|
setting.</p>
|
|
<h4 id="json"><code>json</code></h4>
|
|
<ul>
|
|
<li>Default: false</li>
|
|
<li>Type: Boolean</li>
|
|
</ul>
|
|
<p>Whether or not to output JSON data, rather than the normal output.</p>
|
|
<ul>
|
|
<li>In <code>npm pkg set</code> it enables parsing set values with JSON.parse() before
|
|
saving them to your <code>package.json</code>.</li>
|
|
</ul>
|
|
<p>Not supported by all npm commands.</p>
|
|
<h3 id="see-also">See Also</h3>
|
|
<ul>
|
|
<li><a href="../commands/npm-deny-scripts.html">npm deny-scripts</a></li>
|
|
<li><a href="../commands/npm-install.html">npm install</a></li>
|
|
<li><a href="../commands/npm-rebuild.html">npm rebuild</a></li>
|
|
<li><a href="../configuring-npm/package-json.html">package.json</a></li>
|
|
</ul></div>
|
|
|
|
<footer id="edit">
|
|
<a href="https://github.com/npm/cli/edit/latest/docs/lib/content/commands/npm-approve-scripts.md">
|
|
<svg role="img" viewBox="0 0 16 16" width="16" height="16" fill="currentcolor" style="vertical-align: text-bottom; margin-right: 0.3em;">
|
|
<path fill-rule="evenodd" d="M11.013 1.427a1.75 1.75 0 012.474 0l1.086 1.086a1.75 1.75 0 010 2.474l-8.61 8.61c-.21.21-.47.364-.756.445l-3.251.93a.75.75 0 01-.927-.928l.929-3.25a1.75 1.75 0 01.445-.758l8.61-8.61zm1.414 1.06a.25.25 0 00-.354 0L10.811 3.75l1.439 1.44 1.263-1.263a.25.25 0 000-.354l-1.086-1.086zM11.189 6.25L9.75 4.81l-6.286 6.287a.25.25 0 00-.064.108l-.558 1.953 1.953-.558a.249.249 0 00.108-.064l6.286-6.286z"></path>
|
|
</svg>
|
|
Edit this page on GitHub
|
|
</a>
|
|
</footer>
|
|
</section>
|
|
|
|
|
|
|
|
</body></html> |