Huge W here. This significantly reduces the easy attack surface for NPM supply chain compromise.
Install scripts are off by default.
preinstall,install, andpostinstallfrom dependencies won’t run unless explicitly allowed.
Huge W here. This significantly reduces the easy attack surface for NPM supply chain compromise.
Install scripts are off by default.
preinstall,install, andpostinstallfrom dependencies won’t run unless explicitly allowed.