Hacker News new | ask | show | jobs
by kspetkov79 30 days ago
Postinstall hooks are a footgun. The bad part here is that people reviewing a PHP package may not even look closely at package.json.