• jaybone@lemmy.zip
          link
          fedilink
          English
          arrow-up
          16
          ·
          10 hours ago

          Oh right, I can avoid the full isTrue library implementation with its 8000 dependencies, and instead install the isTrue client, which uses the isTrue cloud service and its REST APIs. Soon it will be AI powered. Then I’ll really be able to tell for sure if my variable value is actually true or not.

          • vrek@programming.dev
            link
            fedilink
            English
            arrow-up
            1
            ·
            4 hours ago

            Look, can I ask a favor? Can you take that, package it, and put it on npm so I can use it in my project?

  • dbx12@programming.dev
    link
    fedilink
    arrow-up
    11
    ·
    15 hours ago

    I only do npm install in a docker container where the project and npm cache is mounted. Gives me a bit of security regarding attacks through post install scripts. (--no-scripts is not an option since I need some of them)

    • Victor@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      4 hours ago

      When do people ever do npm install if you don’t trust the project or know what install scripts will run? I’m a web developer of 10 years and I’ve never run npm install to install a piece of software. The only time I ever run npm is when I’m doing development for work.