Skip to content

feature: Capability to manage npm/jsr/pip dependencies and use specific dependency version for step & scripts #4982

Open
@fengkiej

Description

Feature request for mechanism to manually manage dependency to ensure version compatibility with current code & preventive measures against supply chain attack

Example Attack Scenario

  1. Malicious actor publishes 'left-pad@2.0.0' with harmful code
  2. Script using 'left-pad' auto-updates to compromised version
  3. Malicious code executes within Windmill environment

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions