Skip to content

Conversation

@mook-as
Copy link
Contributor

@mook-as mook-as commented Nov 24, 2025

This disables post-install scripts by default, and only enables a small list that actually uses native components. This potentially papers over the security issue du jour where a compromised package gets scripts added for credential stealing.

This disables post-install scripts by default, and only enables a small
list that actually uses native components.  This potentially papers over
the security issue du jour where a compromised package gets scripts added
for credential stealing.

Signed-off-by: Mark Yen <[email protected]>
@Nino-K Nino-K self-requested a review November 25, 2025 17:50
@Nino-K Nino-K merged commit 0568f46 into rancher-sandbox:main Nov 27, 2025
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants