|
|
|
|
|
by m90
163 days ago
|
|
Wouldn't this just make the number of packages that can be targeted smaller? E.g. I publish a testrunner that needs to install Headless Chrome if not present via postinstall. People trust me and put the package on their allowlist. My account gets compromised and a malicious update is published. People execute malicious code they have never vetted. I do understand this is still better than npm right now, but it's still broken. |
|