npm-audit is good for post-disaster cleanup, but it's too late to prevent anything.
npm-audit is good for post-disaster cleanup, but it's too late to prevent anything.
Well, one way I personally do this for my own stuff is with Docker. The problem is that I don't think it's reasonable to expect every developer to run in Docker - at least until it's at least as easy as the atlernative.
docker run -v "$PWD":/some/app/location ...
My editor doesn't know I'm using Docker. You can change your workflow when you want to deploy to a container registry, etc.
Dev machines are one thing, but there is no reason our CI tools should ever expose credentials in a way that is accessible to any build or test step. Build and test steps should be sandboxed to take input and produce an artifact, which is then uploaded to wherever in a completely separate sandbox.