@selfpentest/pentest-my-ci
v1.1.1
Published
Checks if your CI is vulnerable to an attack from lifecycle scripts
Readme
pentest-my-ci

⚠️ Not intended for actual use.
You can use this package to pentest your own applications to see if they are vulnerable to supply chain attacks.
A package that warns you about the risks of installing from npm with the postinstall scripts enabled.
Usage
npm install -D @selfpentest/pentest-my-ciOnce installed, the package will break your build if it's not secure and display scary but helpful information.
Intent
This package is not a hacking tool. It lets the developer check if their build is vulnerable without making the upfront effort to learn about the supply chain with postinstall scripts. All it does is print a warning. Hopefully a convincing one :)
