{"_id":"@asynq.org/safe-install","_rev":"10-9984eed5b30e8d22abbecec8b63a18f4","name":"@asynq.org/safe-install","dist-tags":{"latest":"0.3.1"},"versions":{"0.1.0":{"name":"@asynq.org/safe-install","version":"0.1.0","keywords":["dependency-security","npm","pnpm","yarn","bun","sandbox","supply-chain","ai-agents"],"author":{"url":"https://asynq.org","name":"Asynq Root","email":"root@asynq.org"},"license":"Apache-2.0","_id":"@asynq.org/safe-install@0.1.0","maintainers":[{"name":"asynq-root","email":"root@asynq.org"}],"homepage":"https://github.com/asynq-org/safe-install#readme","bugs":{"url":"https://github.com/asynq-org/safe-install/issues"},"bin":{"safe-install":"bin/safe-install.js"},"dist":{"shasum":"1c087fd59ff24a2e096a775c1f08e89b4c291192","tarball":"https://registry.npmjs.org/@asynq.org/safe-install/-/safe-install-0.1.0.tgz","fileCount":29,"integrity":"sha512-/bGDS169c0+Y+y56gll8NMjCiQZjWqg4LK18MViQGhZ30suYWBy58mWMpBmHcIPSDDJ3JVAO2iCbR3MuSSxw0g==","signatures":[{"sig":"MEUCICFIyn01BFcOIDxbftQ3OWbMussBHB7yxxATZio/YFntAiEA9ACJzPpld33mxfKusz23ywzygJzYt5lRgNWUwHPC0AE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":128301},"type":"module","engines":{"node":">=20"},"gitHead":"f0a317956943e6ac93f35d1635a11e3ad5784f67","scripts":{"test":"node --test","changelog":"node scripts/generate-changelog.mjs","version:bump":"node scripts/next-version-bump.mjs","changelog:check":"node scripts/generate-changelog.mjs --check"},"_npmUser":{"name":"asynq-root","email":"root@asynq.org"},"repository":{"url":"git+https://github.com/asynq-org/safe-install.git","type":"git"},"_npmVersion":"11.10.0","description":"Local-first safe dependency install gate for JavaScript and TypeScript repositories.","directories":{},"_nodeVersion":"25.6.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/safe-install_0.1.0_1781129963837_0.8851753963762201","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@asynq.org/safe-install","version":"0.1.1","keywords":["dependency-security","npm","pnpm","yarn","bun","sandbox","supply-chain","ai-agents"],"author":{"url":"https://asynq.org","name":"Asynq Root","email":"root@asynq.org"},"license":"Apache-2.0","_id":"@asynq.org/safe-install@0.1.1","maintainers":[{"name":"asynq-root","email":"root@asynq.org"}],"homepage":"https://github.com/asynq-org/safe-install#readme","bugs":{"url":"https://github.com/asynq-org/safe-install/issues"},"bin":{"safe-install":"bin/safe-install.js"},"dist":{"shasum":"6c30f03daf6529947f59268fe23d6c44257716ee","tarball":"https://registry.npmjs.org/@asynq.org/safe-install/-/safe-install-0.1.1.tgz","fileCount":29,"integrity":"sha512-gDfDaYy1Ni7gzytudQT2zrVOp9XFf0moUAwKDMOZi1HDc6Clf959T9TkVKZgPWdgc9k8h24h/M3mnoGhotGiUQ==","signatures":[{"sig":"MEYCIQDrGC8LoaDmN9dXMy0AkOaqaC2Ioxol3jaQVodR1L/cVAIhANTLM6oGHo217spwz9tkDImwai15L89VXXTBafOZKsBU","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@asynq.org%2fsafe-install@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":128457},"type":"module","engines":{"node":">=20"},"gitHead":"8ca151257084c7d8b0da7f9a0fbe35cfec98bad7","scripts":{"test":"node --test","changelog":"node scripts/generate-changelog.mjs","version:bump":"node scripts/next-version-bump.mjs","changelog:check":"node scripts/generate-changelog.mjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2f92c22b-b185-4fb7-9218-75a15f04a513"}},"repository":{"url":"git+https://github.com/asynq-org/safe-install.git","type":"git"},"_npmVersion":"11.13.0","description":"Local-first safe dependency install gate for JavaScript and TypeScript repositories.","directories":{},"_nodeVersion":"24.16.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/safe-install_0.1.1_1781130814233_0.8495215994928473","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@asynq.org/safe-install","version":"0.1.2","keywords":["dependency-security","npm","pnpm","yarn","bun","sandbox","supply-chain","ai-agents"],"author":{"url":"https://asynq.org","name":"Asynq Root","email":"root@asynq.org"},"license":"Apache-2.0","_id":"@asynq.org/safe-install@0.1.2","maintainers":[{"name":"asynq-root","email":"root@asynq.org"}],"homepage":"https://github.com/asynq-org/safe-install#readme","bugs":{"url":"https://github.com/asynq-org/safe-install/issues"},"bin":{"safe-install":"bin/safe-install.js"},"dist":{"shasum":"1bd6a25f9af6b91776f6bec2c0236d32e89abddb","tarball":"https://registry.npmjs.org/@asynq.org/safe-install/-/safe-install-0.1.2.tgz","fileCount":30,"integrity":"sha512-a6CQ/AjQdzM3qnoBMG6b0oKIF1Y1SqlzczR2dcIRBBGUIK5zdMRi6eT/Fe/QBbdaBSK0VL/mW4PNYz+qztkasw==","signatures":[{"sig":"MEYCIQCweDRD2byW4mqImsm25T9h9XaboySc9gNYIZLqIUYP9wIhAMnsFeFt032KKytHSYSsQUx/E18kSpYp8ITLldeFfPC4","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@asynq.org%2fsafe-install@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":128533},"type":"module","engines":{"node":">=20"},"gitHead":"dbefc3201aec17052143c804470baec964a270fa","scripts":{"test":"node --test","changelog":"node scripts/generate-changelog.mjs","version:bump":"node scripts/next-version-bump.mjs","changelog:check":"node scripts/generate-changelog.mjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2f92c22b-b185-4fb7-9218-75a15f04a513"}},"repository":{"url":"git+https://github.com/asynq-org/safe-install.git","type":"git"},"_npmVersion":"11.13.0","description":"Local-first safe dependency install gate for JavaScript and TypeScript repositories.","directories":{},"_nodeVersion":"24.16.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/safe-install_0.1.2_1781132116161_0.12464678959631526","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@asynq.org/safe-install","version":"0.1.3","keywords":["dependency-security","npm","pnpm","yarn","bun","sandbox","supply-chain","ai-agents"],"author":{"url":"https://asynq.org","name":"Asynq Root","email":"root@asynq.org"},"license":"Apache-2.0","_id":"@asynq.org/safe-install@0.1.3","maintainers":[{"name":"asynq-root","email":"root@asynq.org"}],"homepage":"https://github.com/asynq-org/safe-install#readme","bugs":{"url":"https://github.com/asynq-org/safe-install/issues"},"bin":{"safe-install":"bin/safe-install.js"},"dist":{"shasum":"67673a8f5ba937682cb9b4e881bd719ea6334ec5","tarball":"https://registry.npmjs.org/@asynq.org/safe-install/-/safe-install-0.1.3.tgz","fileCount":31,"integrity":"sha512-1Zry1cbUZvG9qfPT5Uwgji05I8/pnGhqdFzeL8JGgFT8BPwIIIW5ZEvkStLjgX/NeMPoJYo7rfCcYgLlpUQ3NA==","signatures":[{"sig":"MEUCIEs0dwoF0UDm0x0jybEAUA9fD/V4UTbbuqARprs8MGiZAiEAk9Lqg0i1z4mNI+5NWrjBmMQaGcWvOhduTD8E7j9u2P0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@asynq.org%2fsafe-install@0.1.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":129226},"type":"module","engines":{"node":">=20"},"gitHead":"0d91c105a9f0e6c53b98e6b1b5d0bc219055d345","scripts":{"test":"node --test","changelog":"node scripts/generate-changelog.mjs","version:bump":"node scripts/next-version-bump.mjs","changelog:check":"node scripts/generate-changelog.mjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2f92c22b-b185-4fb7-9218-75a15f04a513"}},"repository":{"url":"git+https://github.com/asynq-org/safe-install.git","type":"git"},"_npmVersion":"11.13.0","description":"Local-first safe dependency install gate for JavaScript and TypeScript repositories.","directories":{},"_nodeVersion":"24.16.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/safe-install_0.1.3_1781133378693_0.7234445024872083","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"@asynq.org/safe-install","version":"0.1.4","keywords":["dependency-security","npm","pnpm","yarn","bun","sandbox","supply-chain","ai-agents"],"author":{"url":"https://asynq.org","name":"Asynq Root","email":"root@asynq.org"},"license":"Apache-2.0","_id":"@asynq.org/safe-install@0.1.4","maintainers":[{"name":"asynq-root","email":"root@asynq.org"}],"homepage":"https://github.com/asynq-org/safe-install#readme","bugs":{"url":"https://github.com/asynq-org/safe-install/issues"},"bin":{"safe-install":"bin/safe-install.js"},"dist":{"shasum":"b0473a843ba9536622482094a15f49dea8c01c78","tarball":"https://registry.npmjs.org/@asynq.org/safe-install/-/safe-install-0.1.4.tgz","fileCount":31,"integrity":"sha512-0f5oWmLF5ghea+tnFQEhFe2QjqhZgCjX1PsOgrtPw3sS/yyn+L79amY+8ie17MNT6YB3z26xc3tC/bAuTGWKpw==","signatures":[{"sig":"MEUCIBjr8wvFsyjZYQNnYibjgmhsKKIjJH4OesakHBgRqiI5AiEAl2FWU0aldyGgK4CnjfA5RX8bwbHuIkaJURLcdvcR5hg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@asynq.org%2fsafe-install@0.1.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":131458},"type":"module","engines":{"node":">=20"},"gitHead":"63d0fff53c8cf88ac1f3430fc717b1ed7519d796","scripts":{"test":"node --test","changelog":"node scripts/generate-changelog.mjs","version:bump":"node scripts/next-version-bump.mjs","changelog:check":"node scripts/generate-changelog.mjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2f92c22b-b185-4fb7-9218-75a15f04a513"}},"repository":{"url":"git+https://github.com/asynq-org/safe-install.git","type":"git"},"_npmVersion":"11.13.0","description":"Local-first safe dependency install gate for JavaScript and TypeScript repositories.","directories":{},"_nodeVersion":"24.16.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/safe-install_0.1.4_1781135699021_0.8499812439013268","host":"s3://npm-registry-packages-npm-production"}},"0.1.5":{"name":"@asynq.org/safe-install","version":"0.1.5","keywords":["dependency-security","npm","pnpm","yarn","bun","sandbox","supply-chain","ai-agents"],"author":{"url":"https://asynq.org","name":"Asynq Root","email":"root@asynq.org"},"license":"Apache-2.0","_id":"@asynq.org/safe-install@0.1.5","maintainers":[{"name":"asynq-root","email":"root@asynq.org"}],"homepage":"https://github.com/asynq-org/safe-install#readme","bugs":{"url":"https://github.com/asynq-org/safe-install/issues"},"bin":{"safe-install":"bin/safe-install.js"},"dist":{"shasum":"6c9377010866666e34d5380feaa6b73b4fae8f43","tarball":"https://registry.npmjs.org/@asynq.org/safe-install/-/safe-install-0.1.5.tgz","fileCount":31,"integrity":"sha512-qQ4IV2gdYhgAMyIFkQs3z7GkUmvh8mQ9iFHGUppphYP+eOgY5vT/WNSa613a2N6Inf61kpKtEhXzijXmUXRu7w==","signatures":[{"sig":"MEUCIQC0mLW/fsUHvldQgrQ+fnqYAmdfQERPvfXnL6obemlYPgIgJlGRtOzuoqZ0f2azGFdMgPjZxRY2ufyo77INlh7i5cU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@asynq.org%2fsafe-install@0.1.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":133680},"type":"module","engines":{"node":">=20"},"gitHead":"d07150bcc177cab63bef9c41e41038565bee5087","scripts":{"test":"node --test","changelog":"node scripts/generate-changelog.mjs","version:bump":"node scripts/next-version-bump.mjs","changelog:check":"node scripts/generate-changelog.mjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2f92c22b-b185-4fb7-9218-75a15f04a513"}},"repository":{"url":"git+https://github.com/asynq-org/safe-install.git","type":"git"},"_npmVersion":"11.13.0","description":"Local-first safe dependency install gate for JavaScript and TypeScript repositories.","directories":{},"_nodeVersion":"24.16.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/safe-install_0.1.5_1781135932699_0.4899948687004583","host":"s3://npm-registry-packages-npm-production"}},"0.1.6":{"name":"@asynq.org/safe-install","version":"0.1.6","keywords":["dependency-security","npm","pnpm","yarn","bun","sandbox","supply-chain","ai-agents"],"author":{"url":"https://asynq.org","name":"Asynq Root","email":"root@asynq.org"},"license":"Apache-2.0","_id":"@asynq.org/safe-install@0.1.6","maintainers":[{"name":"asynq-root","email":"root@asynq.org"}],"homepage":"https://github.com/asynq-org/safe-install#readme","bugs":{"url":"https://github.com/asynq-org/safe-install/issues"},"bin":{"safe-install":"bin/safe-install.js"},"dist":{"shasum":"906ee4d29f08e4452f9c6632345c4613e15bf800","tarball":"https://registry.npmjs.org/@asynq.org/safe-install/-/safe-install-0.1.6.tgz","fileCount":31,"integrity":"sha512-IhduZObwB5mJDE1EJm9MQeeJ1qbrEFHFHvodWlOlncSHPoJttlA4SxJH6FZdwbuwq4rUOvOIsqQ9X/E1fxg+lg==","signatures":[{"sig":"MEUCIFw9lUTF3Vm4fQLs1XKroMSnDgj/T86DWRlhDvZqkHVnAiEA2q/srwfgI95sDUgXFTuhJHjxzuHcEu2B45DxQm70b2E=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@asynq.org%2fsafe-install@0.1.6","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":135008},"type":"module","engines":{"node":">=20"},"gitHead":"4349c7ef925f7e6eee79d151a201038b0a6406a3","scripts":{"test":"node --test","changelog":"node scripts/generate-changelog.mjs","version:bump":"node scripts/next-version-bump.mjs","changelog:check":"node scripts/generate-changelog.mjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2f92c22b-b185-4fb7-9218-75a15f04a513"}},"repository":{"url":"git+https://github.com/asynq-org/safe-install.git","type":"git"},"_npmVersion":"11.13.0","description":"Local-first safe dependency install gate for JavaScript and TypeScript repositories.","directories":{},"_nodeVersion":"24.16.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/safe-install_0.1.6_1781136687130_0.16116298868065004","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@asynq.org/safe-install","version":"0.2.0","keywords":["dependency-security","npm","pnpm","yarn","bun","sandbox","supply-chain","ai-agents"],"author":{"url":"https://asynq.org","name":"Asynq Root","email":"root@asynq.org"},"license":"Apache-2.0","_id":"@asynq.org/safe-install@0.2.0","maintainers":[{"name":"asynq-root","email":"root@asynq.org"}],"homepage":"https://github.com/asynq-org/safe-install#readme","bugs":{"url":"https://github.com/asynq-org/safe-install/issues"},"bin":{"safe-install":"bin/safe-install.js"},"dist":{"shasum":"30feeec24abe64acc23caf40e9754a5225fe4d1c","tarball":"https://registry.npmjs.org/@asynq.org/safe-install/-/safe-install-0.2.0.tgz","fileCount":31,"integrity":"sha512-RDoKnPUfamH6CgEuDAL9NnaoQIfhmR6xMPRfiWg5k3fhgX1IN65k2eZP+WYxBIB2TcviRXlUpk22oVLM2ubxTQ==","signatures":[{"sig":"MEQCIHSGkX6iFIMTxb7Tp+EiHAXxn4FMkvDp2BwTD7MWktg2AiBDL2Cdwc/IXlib2wldHu46tHvKDdwoIMRWxtDGihr1PA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@asynq.org%2fsafe-install@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":135322},"type":"module","engines":{"node":">=20"},"gitHead":"207729af641dd162450fa76abec157d15dd4dbb7","scripts":{"test":"node --test","changelog":"node scripts/generate-changelog.mjs","version:bump":"node scripts/next-version-bump.mjs","changelog:check":"node scripts/generate-changelog.mjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2f92c22b-b185-4fb7-9218-75a15f04a513"}},"repository":{"url":"git+https://github.com/asynq-org/safe-install.git","type":"git"},"_npmVersion":"11.13.0","description":"Local-first safe dependency install gate for JavaScript and TypeScript repositories.","directories":{},"_nodeVersion":"24.16.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/safe-install_0.2.0_1781137947217_0.6129872813376391","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@asynq.org/safe-install","version":"0.2.1","keywords":["dependency-security","npm","pnpm","yarn","bun","sandbox","supply-chain","ai-agents"],"author":{"url":"https://asynq.org","name":"Asynq Root","email":"root@asynq.org"},"license":"Apache-2.0","_id":"@asynq.org/safe-install@0.2.1","maintainers":[{"name":"asynq-root","email":"root@asynq.org"}],"homepage":"http://safe-install.asynq.org/","bugs":{"url":"https://github.com/asynq-org/safe-install/issues"},"bin":{"safe-install":"bin/safe-install.js"},"dist":{"shasum":"47916e3fc133c8c988b207dafa18de87b715d749","tarball":"https://registry.npmjs.org/@asynq.org/safe-install/-/safe-install-0.2.1.tgz","fileCount":31,"integrity":"sha512-+McgH8Tz7K5XbssMrGwEinLsjWGzBsNkKtaFoj/Sf27vJWETfLzcxFk/nSepUSfbtmfE3t9DZ298mSutLboSQA==","signatures":[{"sig":"MEUCIERfRNHZQqaBeAhKR/agZzrUKbOqT2cPfS/ffdFpeqeMAiEA610sK2f9EuBnEL2y5mryiKxy+w3uVgOiAiANmjGieWA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@asynq.org%2fsafe-install@0.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":135453},"type":"module","engines":{"node":">=20"},"gitHead":"286812967d9f88abda34dc83d1e5856d3ce76aee","scripts":{"test":"node --test","changelog":"node scripts/generate-changelog.mjs","version:bump":"node scripts/next-version-bump.mjs","changelog:check":"node scripts/generate-changelog.mjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2f92c22b-b185-4fb7-9218-75a15f04a513"}},"repository":{"url":"git+https://github.com/asynq-org/safe-install.git","type":"git"},"_npmVersion":"11.13.0","description":"Local-first safe dependency install gate for JavaScript and TypeScript repositories.","directories":{},"_nodeVersion":"24.16.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/safe-install_0.2.1_1781139106965_0.8462313882917247","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@asynq.org/safe-install","version":"0.3.1","description":"Local-first safe dependency install gate for JavaScript and TypeScript repositories.","type":"module","author":{"name":"Asynq Root","email":"root@asynq.org","url":"https://asynq.org"},"bin":{"safe-install":"bin/safe-install.js"},"scripts":{"test":"node --test","changelog":"node scripts/generate-changelog.mjs","changelog:check":"node scripts/generate-changelog.mjs --check","version:bump":"node scripts/next-version-bump.mjs"},"engines":{"node":">=20"},"license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/asynq-org/safe-install.git"},"bugs":{"url":"https://github.com/asynq-org/safe-install/issues"},"homepage":"http://safe-install.asynq.org/","publishConfig":{"access":"public"},"keywords":["dependency-security","npm","pnpm","yarn","bun","sandbox","supply-chain","ai-agents"],"gitHead":"0c865eb7c86ecf34bdc7e40f3abd12169825bd2b","_id":"@asynq.org/safe-install@0.3.1","_nodeVersion":"24.16.0","_npmVersion":"11.13.0","dist":{"integrity":"sha512-AwcFKpb7l2kFfv4PrFLflBAmg+SGGALoIh3o4Y9AX1aZBb4ripcvYfZmozvadMODR8zXdZj8FEvQtpkUC9OFmQ==","shasum":"96fb3fce881421b7d62996a81e640d28c7085626","tarball":"https://registry.npmjs.org/@asynq.org/safe-install/-/safe-install-0.3.1.tgz","fileCount":31,"unpackedSize":136655,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@asynq.org%2fsafe-install@0.3.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCICS6PBtbzg8cgtf+sgINGpiEuhf6bNE6OTSMPXYwc6JEAiBu9y2OEpp3VVEHuIDo0MfLGlzlVEo3e6tn5ochKWVOkw=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2f92c22b-b185-4fb7-9218-75a15f04a513"}},"directories":{},"maintainers":[{"name":"asynq-root","email":"root@asynq.org"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/safe-install_0.3.1_1781173171224_0.3547966536450209"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-10T22:19:23.668Z","modified":"2026-06-11T10:19:31.695Z","0.1.0":"2026-06-10T22:19:24.055Z","0.1.1":"2026-06-10T22:33:34.402Z","0.1.2":"2026-06-10T22:55:16.301Z","0.1.3":"2026-06-10T23:16:18.841Z","0.1.4":"2026-06-10T23:54:59.167Z","0.1.5":"2026-06-10T23:58:52.839Z","0.1.6":"2026-06-11T00:11:27.245Z","0.2.0":"2026-06-11T00:32:27.383Z","0.2.1":"2026-06-11T00:51:47.093Z","0.3.1":"2026-06-11T10:19:31.389Z"},"bugs":{"url":"https://github.com/asynq-org/safe-install/issues"},"author":{"name":"Asynq Root","email":"root@asynq.org","url":"https://asynq.org"},"license":"Apache-2.0","homepage":"http://safe-install.asynq.org/","keywords":["dependency-security","npm","pnpm","yarn","bun","sandbox","supply-chain","ai-agents"],"repository":{"type":"git","url":"git+https://github.com/asynq-org/safe-install.git"},"description":"Local-first safe dependency install gate for JavaScript and TypeScript repositories.","maintainers":[{"name":"asynq-root","email":"root@asynq.org"}],"readme":"# safe-install\n\nLocal-first safe dependency install gate for JavaScript and TypeScript repositories.\n\n[Landing page](http://safe-install.asynq.org/) · [GitHub](https://github.com/asynq-org/safe-install)\n\n`safe-install` wraps package-manager installs and updates in a Docker sandbox before anything touches the real project. It is built for teams and AI coding agents that should not run raw `npm install`, `pnpm update`, `yarn add`, or `bun add` directly.\n\nNo dashboard. No telemetry. No dependency graph upload.\n\n## Status\n\nEarly prototype. Docker is the first implemented sandbox backend. The current implementation isolates install-time code from your real project and real home directory, but it does not yet provide full syscall-level audit such as exact read attempts for every secret path.\n\n## Why\n\nModern supply-chain attacks increasingly execute during dependency installation through lifecycle scripts, build hooks, native build files, or package-manager side effects. Classic dependency scanners mostly ask:\n\n> Is this package known to be bad?\n\n`safe-install` asks a different question:\n\n> What happens when this dependency change is installed?\n\n## Install\n\nInstall in a project:\n\n```bash\nnpm install -D @asynq.org/safe-install\n```\n\nFor local development from this repository:\n\n```bash\nnpm link\n```\n\nThen initialize a project:\n\n```bash\nsafe-install onboarding\n```\n\nThe onboarding flow asks what to enable:\n\n- project policy in `safe-install.yaml`\n- AI agent instructions\n- repo-local package-manager shims\n- lightweight `package.json` guard\n- optional global shims\n- package age and install-script policy\n\nPreview the choices without writing files:\n\n```bash\nsafe-install onboarding --dry-run\n```\n\nUse defaults without prompts:\n\n```bash\nsafe-install onboarding --defaults\n```\n\nManual project setup is still available:\n\n```bash\nsafe-install init --agents --enforce\n```\n\nOptional lightweight `package.json` guard when configuring manually:\n\n```bash\nsafe-install init --package-json-guard\n```\n\nThis adds a `preinstall` script that prints a clear error when someone runs a raw install instead of `safe-install`. It is a guardrail, not hard enforcement, because `--ignore-scripts` can bypass it.\n\nMinimum package age protection is enabled by default at 48 hours. Set `policy.minimumPackageAgeHours` to `168` for a one-week cool-down.\n\n## Usage\n\nInstall or update through the sandbox gate:\n\n```bash\nsafe-install npm install lodash\nsafe-install pnpm update react\nsafe-install yarn add zod\nsafe-install bun add hono\n```\n\nReport only without changing the real project:\n\n```bash\nsafe-install npm install lodash --dry-run\n```\n\nThe default flow is:\n\n1. Copy the project into a temporary sandbox workspace.\n2. Use a fake `HOME` containing only canary placeholder files.\n3. Resolve and fetch dependencies with package scripts disabled.\n4. Run rebuild/build-script detonation in a second Docker container with `--network none`.\n5. Report changed dependency files and suspicious writes.\n6. If the sandbox passes, update the real project with install scripts disabled.\n\n## Reading the Report\n\nThe text report is printed in a box so it stays visually separate from streamed Docker logs.\n\n- `Status` is the final decision. `passed` means the sandbox did not find a blocking issue. `failed` means a sandbox phase returned a non-zero exit code. `blocked` means safe-install detected a policy violation, such as suspicious writes.\n- `Phases` shows the sandbox stages. `resolve-and-fetch` installs or updates dependencies in the copied project with lifecycle scripts disabled. `offline-script-detonation` then runs rebuild/build scripts in a second Docker container with networking disabled.\n- `Tracked dependency files changed` lists lockfiles and manifest files that changed inside the sandbox copy.\n- `Package age checks` lists explicit package specs that were checked against the configured minimum publish age.\n- `Package age warnings` are non-blocking gaps, usually because the command did not include an explicit package name or metadata could not be verified under the current policy.\n- `Package age violations` are blocking publish-age policy failures.\n- `Suspicious writes` means sandboxed scripts changed sensitive paths such as editor, agent, npm, SSH, or cloud credential locations.\n- `Notes` summarizes important sandbox guarantees and apply behavior.\n- `<phase> stderr` is shown only for failed phases and contains the captured package-manager error output.\n\n## Supported Package Managers\n\nInitial JavaScript and TypeScript support:\n\n- `npm`\n- `pnpm`\n- `yarn`\n- `bun`\n\nPython and Rust are planned. See [ROADMAP.md](ROADMAP.md).\n\n## Agent Enforcement\n\n`safe-install init --agents --enforce` writes:\n\n- `AGENTS.md`\n- `CLAUDE.md`\n- `.cursor/rules/safe-install.mdc`\n- `.github/copilot-instructions.md`\n- `.safe-install/bin/npm`\n- `.safe-install/bin/pnpm`\n- `.safe-install/bin/yarn`\n- `.safe-install/bin/bun`\n\nThe generated `.safe-install/` directory is added to `.gitignore`; regenerate these shims per checkout.\n\nAdd the shim directory before normal package managers:\n\n```bash\nexport PATH=\"$PWD/.safe-install/bin:$PATH\"\n```\n\nRaw package-manager commands will be blocked with a message telling the agent to use `safe-install`.\n\nSee [docs/AI_AGENTS.md](docs/AI_AGENTS.md) for the agent policy and [docs/ARCHITECTURE.md](docs/ARCHITECTURE.md) for the sandbox flow.\n\n## package.json Guard\n\nFor projects that do not want shell hooks or global shims, `safe-install init --package-json-guard` adds:\n\n```json\n{\n  \"scripts\": {\n    \"preinstall\": \"safe-install guard npm\"\n  }\n}\n```\n\nRaw `npm install` prints:\n\n```text\nsafe-install guard blocked raw npm install.\nThis repository requires dependency changes to go through safe-install.\n```\n\nThis guard is intentionally lightweight. It cannot stop installs run with `--ignore-scripts`; use CI for team enforcement.\n\n## Global Shims\n\nFor developers who want normal package-manager commands protected across repositories, use optional global shims.\n\nDry run:\n\n```bash\nsafe-install install-global-shims\n```\n\nApply:\n\n```bash\nsafe-install install-global-shims --apply\n```\n\nThen add the shim directory before normal package managers:\n\n```bash\nexport PATH=\"$HOME/.safe-install/shims:$PATH\"\n```\n\nBehavior:\n\n- inside a repository with `safe-install.yaml`, dependency-changing commands are routed through `safe-install`\n- outside such repositories, commands delegate to the real package manager\n- non-dependency commands such as `npm view`, `npm publish`, `npm login`, `npm config`, and `npm run` delegate unchanged\n\nUninstall dry run:\n\n```bash\nsafe-install uninstall-global-shims\n```\n\nUninstall apply:\n\n```bash\nsafe-install uninstall-global-shims --apply\n```\n\nEmergency bypass:\n\n```bash\nSAFE_INSTALL_GLOBAL_SHIM_BYPASS=1 npm install\n```\n\n## Configuration\n\n`safe-install init` writes `safe-install.yaml`:\n\n```yaml\nsandbox:\n  backend: docker\n  minimumIsolation: strong\n  networkDuringBuild: blocked\n  allowFallback: false\n  docker:\n    nodeImage: node:22-bookworm-slim\n    bunImage: oven/bun:1\n    memory: 2g\n    pidsLimit: 256\n\npolicy:\n  minimumPackageAgeHours: 48\n  blockUnverifiedPackageAge: false\n  blockNewInstallScripts: true\n  allowedInstallScriptPackages: []\n  npmRegistry: https://registry.npmjs.org\n```\n\nThe important default is `allowFallback: false`. If strong isolation is required and Docker is unavailable, the install is blocked instead of silently degrading to a weaker mode.\n\n`policy.minimumPackageAgeHours` blocks freshly published direct dependency versions. Set it to `168` for one week, or `0` to disable the age gate.\n\nSet `blockUnverifiedPackageAge: true` if private or unverifiable package metadata should block instead of warn.\n\nPrivate or custom-registry packages are automatically allowed by the package-age policy in this prototype.\n\n`blockNewInstallScripts: true` blocks newly introduced install/build scripts found in parsed lockfile changes unless the package is listed in `allowedInstallScriptPackages`.\n\n## CI\n\nVerify dependency changes in pull requests:\n\n```bash\nsafe-install verify-lockfile --base origin/main\n```\n\nCI entrypoint:\n\n```bash\nsafe-install ci --base origin/main\n```\n\nBoth commands support `--json`. `ci` also requires Docker daemon availability because CI should enforce that the sandbox backend is usable.\n\n## Threat Model\n\nWhat this prototype protects:\n\n- Real SSH keys are not mounted.\n- Real npm tokens are not mounted.\n- Real cloud credentials are not mounted.\n- Real Claude/Cursor/VS Code config is not mounted.\n- Real project files are not mounted during detonation.\n- Build/lifecycle script detonation runs with Docker `--network none`.\n\nWhat it does not yet claim:\n\n- Full syscall audit.\n- Complete detection of secret read attempts.\n- Kernel-level containment beyond Docker's configured isolation.\n- Protection from malicious runtime code after you import and execute a dependency in your app.\n\nThe goal is to reduce install/update blast radius, not prove arbitrary dependency code is safe.\n\n## Development\n\n```bash\nnpm test\nSAFE_INSTALL_E2E=1 npm test\nnpm run changelog\n```\n\n`SAFE_INSTALL_E2E=1` enables Docker-backed end-to-end tests. They are skipped by default when Docker is unavailable.\n\n## Contributing\n\nPull requests are welcome.\n\nGood first contributions include package-manager edge cases, lockfile parsing improvements, CI annotations, documentation, and additional sandbox backends from the roadmap.\n\nBefore opening a PR, run:\n\n```bash\nnpm test\n```\n\nFor changes touching Docker sandbox behavior, also run:\n\n```bash\nSAFE_INSTALL_E2E=1 npm test\n```\n\n## License\n\nCopyright 2026 [Asynq Security](https://asynq.org). Author: Asynq Root <root@asynq.org>.\n\nLicensed under the [Apache License 2.0](LICENSE).\n","readmeFilename":"README.md"}