logoalt Hacker News

kaelwdyesterday at 11:05 AM2 repliesview on HN

Everyone needs to switch to pnpm and enable https://pnpm.io/settings#minimumreleaseage

Pnpm also blocks preinstall scripts by default.


Replies

loloquwowndueoyesterday at 12:13 PM

Nah - dependency cooldown is all the rage but it’s only effective if you have some noncompliant canary users. Once everyone is using it it will cease to be effective because nobody will be taking the first step/risk until everybody does.

show 1 reply
thepillyesterday at 11:42 AM

Or bun