--ignore-scripts vs --filter for credential isolation in CI
0 reputation · 20 Oct 2024, 17:47 UTC
One approach involves using pnpm install --ignore-scripts to globally suppress lifecycle hooks. This prevents postinstall scripts that might load environment variables or connect to external services, but it also risks skipping necessary setup tasks like database migrations or binary compilations.
Alternatively, using pnpm --filter allows for isolating the installation and execution to a specific workspace package. This avoids interacting with unrelated packages that might require secrets, but it does not inherently suppress scripts defined within the targeted package or its direct dependencies.
The uncertainty lies in how these flags interact within complex, nested workspace structures:
- Does combining
--ignore-scriptswith--filterguarantee that no scripts from transitive dependencies are executed? - Is there a recommended method to isolate a test scope while still allowing local setup scripts to run?