• [object Object]@lemmy.ca
    link
    fedilink
    English
    arrow-up
    9
    ·
    12 hours ago

    I think npm allows installation scripts which do make this worse, as a package can run arbitrary command at install time.

    • anyhow2503@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      10 hours ago

      Npm has gotten a few config options that prevent this behaviour. We can only hope that they will become the default eventually.