Browse Source

ci: enforce ignore-scripts policy for Node package managers

securityeng-bot[bot] 1 day ago
parent
commit
c427ea68c5
1 changed files with 2 additions and 0 deletions
  1. 2 0
      nginx-nodejs-redis/web/Dockerfile

+ 2 - 0
nginx-nodejs-redis/web/Dockerfile

@@ -3,6 +3,8 @@ FROM node:14.17.3-alpine3.14
 WORKDIR /usr/src/app
 
 COPY package.json package-lock.json ./
+COPY .npmrc .
+COPY .yarnrc.yml .
 RUN npm ci
 COPY ./server.js ./