npm
Version:
a package manager for JavaScript
341 lines (307 loc) • 11.9 kB
HTML
<html><head>
<meta charset="utf-8">
<title>npm-install-scripts</title>
<style>
body {
background-color: #ffffff;
color: #24292e;
margin: 0;
line-height: 1.5;
font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Helvetica, Arial, sans-serif, "Apple Color Emoji", "Segoe UI Emoji";
}
#rainbar {
height: 10px;
background-image: linear-gradient(139deg, #fb8817, #ff4b01, #c12127, #e02aff);
}
a {
text-decoration: none;
color: #0366d6;
}
a:hover {
text-decoration: underline;
}
pre {
margin: 1em 0px;
padding: 1em;
border: solid 1px #e1e4e8;
border-radius: 6px;
display: block;
overflow: auto;
white-space: pre;
background-color: #f6f8fa;
color: #393a34;
}
code {
font-family: SFMono-Regular, Consolas, "Liberation Mono", Menlo, Courier, monospace;
font-size: 85%;
padding: 0.2em 0.4em;
background-color: #f6f8fa;
color: #393a34;
}
pre > code {
padding: 0;
background-color: inherit;
color: inherit;
}
h1, h2, h3 {
font-weight: 600;
}
#logobar {
background-color: #333333;
margin: 0 auto;
padding: 1em 4em;
}
#logobar .logo {
float: left;
}
#logobar .title {
font-weight: 600;
color: #dddddd;
float: left;
margin: 5px 0 0 1em;
}
#logobar:after {
content: "";
display: block;
clear: both;
}
#content {
margin: 0 auto;
padding: 0 4em;
}
#table_of_contents > h2 {
font-size: 1.17em;
}
#table_of_contents ul:first-child {
border: solid 1px #e1e4e8;
border-radius: 6px;
padding: 1em;
background-color: #f6f8fa;
color: #393a34;
}
#table_of_contents ul {
list-style-type: none;
padding-left: 1.5em;
}
#table_of_contents li {
font-size: 0.9em;
}
#table_of_contents li a {
color: #000000;
}
header.title {
border-bottom: solid 1px #e1e4e8;
}
header.title > h1 {
margin-bottom: 0.25em;
}
header.title > .description {
display: block;
margin-bottom: 0.5em;
line-height: 1;
}
header.title .version {
font-size: 0.8em;
color: #666666;
}
footer#edit {
border-top: solid 1px #e1e4e8;
margin: 3em 0 4em 0;
padding-top: 2em;
}
table {
width: 100%;
margin: 1em 0;
border-radius: 6px;
border: 1px solid #e1e4e8;
overflow: hidden;
border-collapse: separate;
border-spacing: 0;
}
table thead {
background-color: #f6f8fa;
}
table tbody {
background-color: #ffffff;
}
table th,
table td {
padding: 0.75em;
text-align: left;
border-right: 1px solid #e1e4e8;
border-bottom: 1px solid #e1e4e8;
}
table th:last-child,
table td:last-child {
border-right: none;
}
table tbody tr:last-child td {
border-bottom: none;
}
table th {
font-weight: 600;
background-color: #f6f8fa;
}
table code {
white-space: nowrap;
}
</style>
</head>
<body>
<div id="banner">
<div id="rainbar"></div>
<div id="logobar">
<svg class="logo" role="img" height="32" width="32" viewBox="0 0 700 700">
<polygon fill="#cb0000" points="0,700 700,700 700,0 0,0"></polygon>
<polygon fill="#ffffff" points="150,550 350,550 350,250 450,250 450,550 550,550 550,150 150,150"></polygon>
</svg>
<div class="title">
npm command-line interface
</div>
</div>
</div>
<section id="content">
<header class="title">
<h1 id="----npm-install-scripts----1201">
<span>npm-install-scripts</span>
<span class="version">@12.0.1</span>
</h1>
<span class="description">Manage install-script approvals for dependencies</span>
</header>
<section id="table_of_contents">
<h2 id="table-of-contents">Table of contents</h2>
<div id="_table_of_contents"><ul><li><a href="#synopsis">Synopsis</a></li><li><a href="#description">Description</a></li><li><a href="#examples">Examples</a></li><li><a href="#configuration">Configuration</a></li><ul><li><a href="#all"><code>all</code></a></li><li><a href="#allow-scripts-pin"><code>allow-scripts-pin</code></a></li><li><a href="#dry-run"><code>dry-run</code></a></li><li><a href="#json"><code>json</code></a></li></ul><li><a href="#see-also">See Also</a></li></ul></div>
</section>
<div id="_content"><h3 id="synopsis">Synopsis</h3>
<pre><code class="language-bash">npm install-scripts approve <pkg> [<pkg> ...]
npm install-scripts approve --all
npm install-scripts deny <pkg> [<pkg> ...]
npm install-scripts deny --all
npm install-scripts ls
npm install-scripts prune
</code></pre>
<p>Note: This command is unaware of workspaces.</p>
<h3 id="description">Description</h3>
<p>Manages the <code>allowScripts</code> field in your project's <code>package.json</code>, which
records which of your dependencies are permitted to run install scripts
(<code>preinstall</code>, <code>install</code>, <code>postinstall</code>, and <code>prepare</code> for non-registry
sources). This is the recommended way to maintain that field.</p>
<p>Dependency install scripts are blocked by default. Install commands
silently skip lifecycle scripts for any dependency that does not have a
matching entry in <code>allowScripts</code>, and end with a list of the packages
whose scripts were skipped so you can review them here.</p>
<p>This command only works inside a project that has a <code>package.json</code>. Running
it with <code>--global</code> (<code>-g</code>) fails with an <code>EGLOBAL</code> error, since global
installs (<code>npm install -g</code>) and one-off executions (<code>npm exec</code> / <code>npx</code>) have
no project <code>package.json</code> to write to. To allow install scripts in those
contexts, use the <code>--allow-scripts</code> flag at install time (for example
<code>npm install -g --allow-scripts=canvas,sharp</code>) or persist the setting with
<code>npm config set allow-scripts=canvas,sharp --location=user</code>.</p>
<p>There are four subcommands:</p>
<pre><code class="language-bash">npm install-scripts approve <pkg> [<pkg> ...]
npm install-scripts approve --all
npm install-scripts deny <pkg> [<pkg> ...]
npm install-scripts deny --all
npm install-scripts ls
npm install-scripts prune
</code></pre>
<p><code>approve</code> allows install scripts for the named packages. <code><pkg></code> matches
every installed version of that package. By default it writes pinned entries
(<code>pkg@1.2.3</code>), which keep their approval narrowed to the specific version you
reviewed. Pass <code>--no-allow-scripts-pin</code> to write name-only entries that allow
any future version. <code>--all</code> approves every package with unreviewed install
scripts in one go.</p>
<p><code>deny</code> records an explicit denial for the named packages (a name-only <code>false</code>
entry), which survives <code>npm install-scripts approve --all</code> and excludes the
package from any future blanket approval. <code>--all</code> denies every package with
unreviewed install scripts.</p>
<p><code>ls</code> is read-only: it lists every package whose install scripts are not yet
covered by <code>allowScripts</code>, without modifying <code>package.json</code>.</p>
<p><code>prune</code> removes <code>allowScripts</code> entries that no longer match an installed
package with an install script, either because the package is no longer
installed (a transitive dependency changed, or a pinned <code>pkg@1.2.3</code> was
upgraded) or because it no longer has an install script. Both approvals
(<code>true</code>) and denials (<code>false</code>) are removed. It edits only the <code>allowScripts</code>
field in <code>package.json</code>, never <code>.npmrc</code> or <code>--allow-scripts</code>. Pass <code>--dry-run</code>
to preview without writing. Unparseable keys are left alone.</p>
<p><code>approve</code> honours the asymmetric pin rule: if you re-approve a package whose
installed version has changed, the existing pin is rewritten to track the new
installed version. Multi-version statements (<code>pkg@1 || 2</code>) are left alone,
since they likely capture intent that the command cannot infer. Existing
<code>false</code> entries always win; <code>approve</code> will not silently re-allow a package you
previously denied.</p>
<p>The standalone commands <a href="../commands/npm-approve-scripts.html"><code>npm approve-scripts</code></a>
and <a href="../commands/npm-deny-scripts.html"><code>npm deny-scripts</code></a> are aliases for
<code>npm install-scripts approve</code> and <code>npm install-scripts deny</code>.</p>
<h3 id="examples">Examples</h3>
<pre><code class="language-bash"># Approve all currently-installed install scripts after reviewing them
npm install-scripts approve --all
# Approve specific packages, pinned to their installed version
npm install-scripts approve canvas sharp
# Deny a package so it stays blocked
npm install-scripts deny telemetry-pkg
# Preview which packages still need review
npm install-scripts ls
# Preview stale allowScripts entries, then remove them
npm install-scripts prune --dry-run
npm install-scripts prune
</code></pre>
<h3 id="configuration">Configuration</h3>
<h4 id="all"><code>all</code></h4>
<ul>
<li>Default: false</li>
<li>Type: Boolean</li>
</ul>
<p>Show or act on all packages, not just the ones your project directly depends
on. For <code>npm outdated</code> and <code>npm ls</code> this lists every outdated or installed
package. For <code>npm approve-scripts</code> and <code>npm deny-scripts</code> it selects every
package with pending install scripts.</p>
<h4 id="allow-scripts-pin"><code>allow-scripts-pin</code></h4>
<ul>
<li>Default: true</li>
<li>Type: Boolean</li>
</ul>
<p>Write pinned (<code>pkg@version</code>) entries when approving install scripts. Set to
<code>false</code> to write name-only entries that allow any version. Has no effect on
<code>npm deny-scripts</code>, which always writes name-only entries regardless of this
setting.</p>
<h4 id="dry-run"><code>dry-run</code></h4>
<ul>
<li>Default: false</li>
<li>Type: Boolean</li>
</ul>
<p>Indicates that you don't want npm to make any changes and that it should
only report what it would have done. This can be passed into any of the
commands that modify your local installation, eg, <code>install</code>, <code>update</code>,
<code>dedupe</code>, <code>uninstall</code>, as well as <code>pack</code> and <code>publish</code>.</p>
<p>Note: This is NOT honored by other network related commands, eg <code>dist-tags</code>,
<code>owner</code>, etc.</p>
<h4 id="json"><code>json</code></h4>
<ul>
<li>Default: false</li>
<li>Type: Boolean</li>
</ul>
<p>Whether or not to output JSON data, rather than the normal output.</p>
<ul>
<li>In <code>npm pkg set</code> it enables parsing set values with JSON.parse() before
saving them to your <code>package.json</code>.</li>
</ul>
<p>Not supported by all npm commands.</p>
<h3 id="see-also">See Also</h3>
<ul>
<li><a href="../commands/npm-approve-scripts.html">npm approve-scripts</a></li>
<li><a href="../commands/npm-deny-scripts.html">npm deny-scripts</a></li>
<li><a href="../commands/npm-install.html">npm install</a></li>
<li><a href="../commands/npm-rebuild.html">npm rebuild</a></li>
<li><a href="../configuring-npm/package-json.html">package.json</a></li>
</ul></div>
<footer id="edit">
<a href="https://github.com/npm/cli/edit/latest/docs/lib/content/commands/npm-install-scripts.md">
<svg role="img" viewBox="0 0 16 16" width="16" height="16" fill="currentcolor" style="vertical-align: text-bottom; margin-right: 0.3em;">
<path fill-rule="evenodd" d="M11.013 1.427a1.75 1.75 0 012.474 0l1.086 1.086a1.75 1.75 0 010 2.474l-8.61 8.61c-.21.21-.47.364-.756.445l-3.251.93a.75.75 0 01-.927-.928l.929-3.25a1.75 1.75 0 01.445-.758l8.61-8.61zm1.414 1.06a.25.25 0 00-.354 0L10.811 3.75l1.439 1.44 1.263-1.263a.25.25 0 000-.354l-1.086-1.086zM11.189 6.25L9.75 4.81l-6.286 6.287a.25.25 0 00-.064.108l-.558 1.953 1.953-.558a.249.249 0 00.108-.064l6.286-6.286z"></path>
</svg>
Edit this page on GitHub
</a>
</footer>
</section>
</body></html>