• [object Object]@lemmy.ca
    link
    fedilink
    English
    arrow-up
    10
    ·
    1 day ago

    I think npm allows installation scripts which do make this worse, as a package can run arbitrary command at install time.

    • anyhow2503@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      Npm has gotten a few config options that prevent this behaviour. We can only hope that they will become the default eventually.