
Security News
GitHub Actions Adds cache-mode to Limit Cache Poisoning Risk
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.
@abdoknbgit/tau-installer
Advanced tools
Install Tau globally with its reviewed npm lifecycle scripts allowed for this install only.
@abdoknbgit/tau-installer installs Tau globally. On npm 11.16 and newer, it
allows only Tau's reviewed npm lifecycle scripts for that single install
command. Older npm versions use npm's normal lifecycle-script behavior because
they do not support the command-scoped policy.
Node.js 20.18.1 or newer is required.
npx -y @abdoknbgit/tau-installer@latest
Tau's updater can pin the release it already selected:
npx -y @abdoknbgit/tau-installer@latest --tau-version 0.92.15
--tau-version accepts an exact semantic version only. Tags and ranges such as
latest, ^0.92.15, and 0.92.x are rejected.
npx -y @abdoknbgit/tau-installer@latest --dry-run
The installer has no dependencies and no lifecycle scripts of its own. It runs
the invoking npm CLI with shell: false. On npm 11.16 and newer, it passes the
reviewed list through a command-line --allow-scripts option. It never runs
npm config set and never changes the user's persistent npm configuration.
For this command only, the installer also disables inherited ignore-scripts
and dangerously-allow-all-scripts settings, disables inherited npm dry-run
and package-lock-only modes, forces executable bin links, includes supported
optional dependencies, and, where supported, enables strict script policy. On
npm 11.16 and newer, required reviewed scripts can run while an unreviewed
dependency script stops the install.
The installer checks the invoking npm version first. npm 11.16 and newer receive
the command-only --allow-scripts list. Older npm versions omit that unsupported
option because they run lifecycle scripts normally.
Tau's release tests derive the reviewed list from package-lock.json and fail
when a production dependency adds or removes an install script. This keeps the
installer policy explicit without changing users' persistent npm configuration.
FAQs
Install Tau globally with its reviewed npm lifecycle scripts allowed for this install only.
The npm package @abdoknbgit/tau-installer receives a total of 7 weekly downloads. As such, @abdoknbgit/tau-installer popularity was classified as not popular.
We found that @abdoknbgit/tau-installer demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.

Research
/Security News
A Twitch browser extension on Chrome and Firefox forwards users’ live OAuth session tokens through proxies controlled by a Russian bot service.