8000 Chore: Do not send user secret in the referer header by assapir · Pull Request #1663 · npm/cli · GitHub
[go: up one dir, main page]

Skip to content

Conversation

assapir
Copy link
@assapir assapir commented Aug 12, 2020

Until now, CLI is sending the command line args in the referer header, which might be logged.

@assapir assapir requested a review from a team August 12, 2020 10:08
@npm-deploy-user
Copy link
npm-deploy-user commented Aug 12, 2020
angular-quickstart app-large app-medium ember-quickstart react-app
prev current status prev current status prev current status prev current status prev current status
initial install 41s 31.1s 39.5s 36.4s 34.5s 31s 28.1s 20.4s 33.5s 27.7s
repeat install 9.6s 7.1s 8.6s 6.7s 8.3s 5.9s 7.7s 5.5s 9.1s 6.7s
with warm cache 32.3s 24.7s 33.8s 30.1s 31.3s 22.8s 23.4s 17.4s 29.1s 23.5s
with node_modules 9.2s 6.3s 8.6s 5.9s 9s 5.5s 7.8s 5.3s 9.4s 6.2s
with lockfile 32.6s 23.9s 31s 26.2s 29s 23.1s 21.7s 16.3s 27.4s 22.4s
with warm cache and node_modules 9.3s 6.8s 7.9s 6s 8.4s 5.4s 7.6s 5.4s 9.2s 6.3s
with warm cache and lockfile 24.7s 18.4s 26.3s 22s 24.3s 16.4s 17.8s 12.4s 21.3s 17.5s
with node_modules and lockfile 10.1s 7.3s 9.8s 7s 8.6s 6.7s 7.8s 5.7s 9.7s 7.2s

@assapir assapir requested review from darcyclarke and a team August 13, 2020 05:27
@rami548
A77C Copy link
rami548 commented Apr 16, 2021

@natester605 natester605 mentioned this pull request Sep 25, 2021
@nlf nlf deleted the assapir/redact-password branch March 28, 2022 16:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Enhancement new feature or improvement Release 6.x work is associated with a specific npm 6 release semver:patch semver patch level for changes
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants
0