logoalt Hacker News

joeblubaughtoday at 2:32 AM1 replyview on HN

There has been a lot of pain at my various jobs installing a safe global npm config on every developer machine, asking people not to disable it, checking it with mdm tools. A safer out-of-the-box configuration is long overdue.


Replies

tkeltoday at 2:36 AM

Just dont use npm. Use a package manager which doesn't execute postinstall by default. The switch is incredibly simple.

show 1 reply