logoalt Hacker News

mechazawatoday at 1:55 PM2 repliesview on HN

iirc does pnpm not allow them by default. But even if we killed them off there would still be a chance of the malware hooking into something else or only working in cli applications.


Replies

madeofpalktoday at 5:17 PM

The latest version of all node package managers (npm, yarn, pnpm) now deny this by default. pnpm was ahead of the curve.

jonchurch_today at 4:57 PM

npm v12 released last month also defaults into blocking them by default