logoalt Hacker News

johnny22today at 8:39 AM1 replyview on HN

glad pnpm disables those by default!


Replies

skeeter2020today at 1:04 PM

PSA: if you're using (a newish release of) npm you should have something like this as a default, unless you've got good reasons not to:

min-release-age=7 # days

ignore-scripts=true