Supply Chain Attacks
Netlify Build Plugins as arbitrary code execution at build time in 2026
The @netlify/plugin-* ecosystem runs in your build with full filesystem and network access. Here is how to evaluate, allowlist, and gate it in 2026.
May 14, 20267 min read