Skip to content

v1.1.0 — bounded deep package scanning

Latest

Choose a tag to compare

@github-actions github-actions released this 29 Aug 09:50
· 5 commits to main since this release
v1.1.0
8443979

Highlights

  • Adds opt-in bounded tarball inspection with same-origin enforcement, integrity verification, safe in-memory TAR parsing, and strict size limits.
  • Adds --deep to package checks, batch checks, CI scans, and the install gate.
  • Detects remote shell pipelines, encoded dynamic execution, process/network combinations, sensitive environment access, and native executable content.
  • Redacts credentials and arbitrary setting values from local command logs.
  • Strengthens lifecycle-script reporting, release verification, documentation, and contributor workflows.

Install or upgrade

npm install -g @npm-safe/core@1.1.0

CI passes on Node.js 20.12 and 24. The npm package is published with SLSA provenance. Desktop assets are attached below.