logoalt Hacker News

efortisyesterday at 1:26 PM1 replyview on HN

Mitigate this attack vector by adding:

  ignore-scripts=true
to your .npmrc

https://blog.uxtly.com/getting-rid-of-npm-scripts


Replies

herpdyderpyesterday at 2:15 PM

Also add it to ~/.npmrc!

show 1 reply