logoalt Hacker News

ohsecurityyesterday at 2:48 PM2 repliesview on HN

[flagged]


Replies

bspammeryesterday at 3:30 PM

In case you haven't seen, AI-written comments were recently banned here

https://news.ycombinator.com/item?id=47340079

philipwhiukyesterday at 3:05 PM

> At that point, “npm install” feels less like importing a library and more like executing a supply chain

Which is why pre and post install scripts should never had been added.