灵感菇

AI 技能的自然生态,你的一句话,蔓延出无限连接。

返回搜索

安全与治理 / 审核评估

npm-git-install

npm-git-install

安装量 110GitHub Stars 14更新时间 2026年5月16日

描述

Route Node package-delivery ambiguity into one install packet: temporary Git bridge, SHA-pinned shared bridge, private-auth Git path, tarball / `npm pack` artifact, workspace / `file:` inner-loop, or publish-first registry handoff. Use when the user wants to install an npm / pnpm / Yarn / Bun package from a branch, tag, commit, fork, private repo, monorepo package, or unreleased fix, and the real question is which delivery path is safest rather than how Git or package registries work in general. Triggers on: npm install from GitHub, git dependency, github:owner/repo, git+ssh, git+https, private package from repo, install branch vs commit, monorepo package install, npm pack vs git, and should we publish this instead.

安全审计

使用前的风险提示

未审计

规则审计

未审计
更新 1年1月1日

智能审计

未审计
更新 1年1月1日
uiauthgithubnpmgitinstallroutenodepackagedeliveryambiguityone