logoalt Hacker News

toygtoday at 10:28 AM1 replyview on HN

that's a willing act - you are actively asking npm to download something, and accepting it might be terrible for you.

Here chrome is just installing things behind your back, whether you really want it or not.


Replies

yearolinuxdsktptoday at 12:16 PM

Never use “npm install”, only “npm ci”. Using “npm install” is a willing act to run fresh exploits.