logoalt Hacker News

arcfourtoday at 4:57 AM1 replyview on HN

PNPM makes you approve postinstall scripts instead of running them by default, which helps a lot. Whenever I see a prompt to run a postinstall script, unless I know the package normally has one & what it does, I go look it up before approving it.

(Of course I could still get bitten if one of the packages I trust has its postinstall script replaced.)


Replies

erikeriksontoday at 2:25 PM

How does this stance work with your CICD?

show 1 reply