Title: Manage npm packages used in workflows · Issue #2571 · nodejs/docker-node · GitHub
Open Graph Title: Manage npm packages used in workflows · Issue #2571 · nodejs/docker-node
X Title: Manage npm packages used in workflows · Issue #2571 · nodejs/docker-node
Description: What would you like? Add an npm private (non-publishable) package.json to allow managing and pinning npm dependencies used in GitHub Actions workflows. Why is this needed? Best practices for GitHub repos have evolved in the face of suppl...
Open Graph Description: What would you like? Add an npm private (non-publishable) package.json to allow managing and pinning npm dependencies used in GitHub Actions workflows. Why is this needed? Best practices for GitHub...
X Description: What would you like? Add an npm private (non-publishable) package.json to allow managing and pinning npm dependencies used in GitHub Actions workflows. Why is this needed? Best practices for GitHub...
Opengraph URL: https://github.com/nodejs/docker-node/issues/2571
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Manage npm packages used in workflows","articleBody":"## What would you like?\n\nAdd an npm [private](https://docs.npmjs.com/cli/v11/configuring-npm/package-json#private) (non-publishable) [package.json](https://docs.npmjs.com/cli/v11/configuring-npm/package-json) to allow managing and pinning npm dependencies used in GitHub Actions workflows.\n\n## Why is this needed?\n\nBest practices for GitHub repos have evolved in the face of supply-chain attacks, and favor pinning dependencies instead of allowing `latest` or SemVer ranges.\n\n[Code-scanning alerts](https://github.com/nodejs/docker-node/security/code-scanning) for the repo, report \"Pinned-Dependencies\" for three GitHub Actions [.github/workflows](https://github.com/nodejs/docker-node/tree/main/.github/workflows):\n\n| Workflow | npm Package |\n| -------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------- |\n| [doctoc.yml](https://github.com/nodejs/docker-node/blob/main/.github/workflows/doctoc.yml) | [doctoc](https://www.npmjs.com/package/doctoc) |\n| [eclint.yml](https://github.com/nodejs/docker-node/blob/main/.github/workflows/eclint.yml) | [eclint](https://www.npmjs.com/package/eclint) |\n| [markdown-link-check.yml](https://github.com/nodejs/docker-node/blob/main/.github/workflows/markdown-link-check.yml) | [markdown-link-check@3.14.2](npmjs.com/package/markdown-link-check) |\n\n## Other\n\nPR https://github.com/nodejs/docker-node/pull/2570 proposes to replace `eclint` with `prettier`. In this case, `prettier` would be added to the `package.json` instead of `eclint`.","author":{"url":"https://github.com/MikeMcC399","@type":"Person","name":"MikeMcC399"},"datePublished":"2026-07-20T17:15:32.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":3},"url":"https://github.com/2571/docker-node/issues/2571"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:39ed4315-584f-3599-2133-3855a4175fda |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | 95E8:614FA:15DC7E:1E1E59:6A626503 |
| html-safe-nonce | 247c3c2e636a7ecdd64ecf8eba3967e3b76ea9603dfcf389f3522277d13634c1 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI5NUU4OjYxNEZBOjE1REM3RToxRTFFNTk6NkE2MjY1MDMiLCJ2aXNpdG9yX2lkIjoiNTExMTkzMzMwMzY5NzU5NzY5OSIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | a0223a754dc483ede27ab0327de7f74d0a4646810b65e1b2508f182aa0e94a8d |
| hovercard-subject-tag | issue:4931292737 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/nodejs/docker-node/2571/issue_layout |
| twitter:image | https://opengraph.githubassets.com/770ee95bcb97d928c784d13e14a0b07f3eb807b9c14c25449461e4ce11d10ada/nodejs/docker-node/issues/2571 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/770ee95bcb97d928c784d13e14a0b07f3eb807b9c14c25449461e4ce11d10ada/nodejs/docker-node/issues/2571 |
| og:image:alt | What would you like? Add an npm private (non-publishable) package.json to allow managing and pinning npm dependencies used in GitHub Actions workflows. Why is this needed? Best practices for GitHub... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | MikeMcC399 |
| hostname | github.com |
| expected-hostname | github.com |
| None | 194bddaed53c0eb07047629c520853f4208e77a17ff57428346485cc202e39f2 |
| turbo-cache-control | no-preview |
| go-import | github.com/nodejs/docker-node git https://github.com/nodejs/docker-node.git |
| octolytics-dimension-user_id | 9950313 |
| octolytics-dimension-user_login | nodejs |
| octolytics-dimension-repository_id | 27929056 |
| octolytics-dimension-repository_nwo | nodejs/docker-node |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 27929056 |
| octolytics-dimension-repository_network_root_nwo | nodejs/docker-node |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | c2862cf2db52f0c7f6cba3de21ffeeafe7c5456e |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width