logoalt Hacker News

sysguestyesterday at 7:06 PM2 repliesview on HN

yeah it's such a pity deno's security features could have made recent npm attacks moot...


Replies

sheeptyesterday at 7:15 PM

The recent npm supply chain attacks relied on lifecycle scripts, which Deno doesn't run by default, but neither do pnpm or Bun. While Deno, like npm, supports a minimum release age, it doesn't enable it by default.

show 1 reply
cyanydeezyesterday at 7:16 PM

the problem was at the start of deno, it didn't integrate with npm; the same way Macintosh used to be free of virus and trojan horses was because people just didn't use it enough.