Repository navigation
nvx 0.7.0 is the first signed release. nvx.exe carries an Authenticode signature from a Certum certificate issued to "Open Source Developer Felix Stubner". SmartScreen may still warn on the first downloads while the certificate builds a reputation.
Install
irm https://raw.githubusercontent.com/fstubner/nvx/v0.7.0/install.ps1 | iexcurl -fsSL https://raw.githubusercontent.com/fstubner/nvx/v0.7.0/install.sh | shnpm install -g @fstubner/nvxThe npm package installs the binary for your platform and runs no install script.
Highlights
Installs
- pnpm installs inside the Windows sandbox, the first time and every time after.
- bun's package manager cannot run in the Windows sandbox outside the drive Windows is installed on. That is a bun limitation, and nvx now names the cause after the failure.
- The pre-install checks run on every package an npm install brings in, and a lockfile entry must match the registry's record of it.
- Packages from a private registry are checked on that registry, and contained installs work behind a corporate proxy.
- The typosquat check runs only on names you chose, and a command that already turns install scripts off is not asked about them.
Containment
- On macOS a contained install can no longer read your credential files.
- On macOS a contained install can write only to the project, its own home and a few device files such as
/dev/null. It can no longer write the system temp folders or other apps' caches. - A contained install can no longer write the project's
.git. - On Linux a contained process can no longer reach the host's UNIX sockets, and killing nvx stops the contained process.
Setup and shells
nvx setuptakes seconds instead of minutes on a large drive, and covers every fixed drive in one run.- fish and cmd.exe are supported shells.
NVX_NODE_MIRRORfetches Node.js from a mirror.- The shims run the version a project pins, with or without the shell hook.
Policy and audit
- A global policy can be a baseline that a project cannot weaken.
- New commands:
nvx policy explain,nvx policy checkandnvx audit export.
Releases carry SHA-256 checksums and a build-provenance attestation as before. gh attestation verify nvx.exe --repo fstubner/nvx checks a download (GitHub CLI 2.49 or newer).
The full list, over a hundred changes, is in the changelog.