Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
0 points
blktiger
4mo ago
0 comments
Share
Both NPM and Yarn have a way to disable install scripts which everyone should do if at all possible.
undefined | Better HN
0 comments
default
newest
oldest
twistedpair
4mo ago
Good point, but until many popular packages stop requiring install.sh to operate, you'll still need to allowlist some of them. That is built into the PNPM tooling, luckily :)
j
/
k
navigate · click thread line to collapse