Skip to content

[Feature]: Pin all NPM packages with their commit hash #847

Description

@MacOS

🧠 D: DOCUMENT — Problem & Opportunity

What is the problem, limitation, or opportunity? Why does this matter for SKaiNET?

Explain the context in clear terms:

  • What functionality is missing or insufficient?
  • Why is this important now?
  • Who benefits (users, developers, researchers)?
  • What is the high-level goal of this proposal?

Currently, two npm install commands pin the pachage by tag. This is a potential security vulnerability, against best practises, and lowers the OpenSSF Score. We therefore want to pin them with their commit hashes instead.

Summary (1–2 sentences):

Provide a concise overview of what this issue aims to address.

This issue addresse the potential security threat caused by packages pinned with tags.

🔍 A: ASSESS — Feasibility & Impact

Provide an evaluation of the proposal. Address the following:

✔️ Feasibility

  • Is the feature straightforward to implement?
  • Are there architectural constraints?

It is straightforward to switch from pinned tags to pinned commit hashes.

✔️ Expected Impact

  • How does this improve SKaiNET?
  • Does it unlock new capabilities?

It improves SKaiNET by improving it's security.

✔️ Risks / Constraints

  • Technical challenges?
  • Numerical stability concerns?
  • API consistency?

None.

✔️ Dependencies

  • Does this rely on an existing SKaiNET module?
  • Does it require third-party libraries or standards?

None.

📚 R: RESEARCH — What Must Be Understood First?

Document research tasks or open questions that must be answered before implementation:

Research Tasks

  • Review existing frameworks (PyTorch, JAX, TensorFlow, etc.)
  • Identify relevant algorithms or formulas
  • Compare design patterns for modularity
  • Investigate numerically stable or optimized variants
  • Check for relevant academic papers or benchmarks

Not applicable.

Open Questions

List unknowns that contributors should discuss or resolve.

There are no open questions.

🛠️ C: CODE — Implementation Plan

Break down actionable steps required to deliver this feature:

Development Tasks

  • Dockerfile in docs
  • documentation.yml

Acceptance Criteria

  • Dockerfile in docs
  • documentation.yml

💬 Additional Notes

Add diagrams, pseudo-code, references, or implementation notes that may help future contributors.

Metadata

Metadata

Assignees

Labels

documentationImprovements or additions to documentationenhancementNew feature or requestgithub_actionsPull requests that update GitHub Actions code

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions