logoalt Hacker News

mkesperyesterday at 10:33 AM0 repliesview on HN

At least make them run pnpm instead of npm, disabling post-install scripts. https://pnpm.io/supply-chain-security