Hacker News new | ask | show | jobs
by eknkc 273 days ago
I've been using pnpm and it does not run lifecycle scripts by default. Asks for confirmation and creates a whitelist if you allow things. Might be the better default.