• [object Object]@lemmy.ca
    link
    fedilink
    English
    arrow-up
    7
    ·
    4 hours ago

    I think npm allows installation scripts which do make this worse, as a package can run arbitrary command at install time.

    • anyhow2503@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 hours ago

      Npm has gotten a few config options that prevent this behaviour. We can only hope that they will become the default eventually.