Hacker News new | ask | show | jobs
by johnny22 65 days ago
glad pnpm disables those by default!
1 comments

PSA: if you're using (a newish release of) npm you should have something like this as a default, unless you've got good reasons not to:

min-release-age=7 # days

ignore-scripts=true