Hacker News new | ask | show | jobs
by josephg 34 days ago
Yeah. Or they should run in a sandbox. I would have no problem with a post install script which ran arbitrary commands in the context of the installed package itself. But arbitrary scripts + user level permissions is a recipe for disaster.

That said, packages could still just run whatever junk they want when they first get imported in a program.