At least make them run pnpm instead of npm, disabling post-install scripts. https://pnpm.io/supply-chain-security