CapLock - Tagline короче сделай Sandbox npm & pnpm install scripts.

by•
CapLock is a cross-platform CLI that protects npm and pnpm projects from malicious lifecycle scripts. It intercepts scripts like postinstall and runs them inside a restricted sandbox with filesystem, environment, network, and child-process isolation

Add a comment

Replies

Best
I built CapLock after thinking about how much trust we give dependency install scripts by default.A malicious postinstall can potentially read secrets, modify project files, spawn child processes, or make network requests before you even run the package. CapLock puts those scripts behind a policy-controlled sandbox. Current protections include: - .env / secret access blocking - project-root write protection - child-process containment - default-deny network policy - npm + pnpm support - Windows, Linux, and macOS support Would love feedback from developers working with Node.js, package security, or supply-chain tooling.