Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse

NodeBB

  1. Home
  2. uncategorized
  3. Really, another npm attack?

Really, another npm attack?

Scheduled Pinned Locked Moved uncategorized
5 Posts 3 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • volpeon@icy.wyvern.ripV This user is from outside of this forum
    volpeon@icy.wyvern.ripV This user is from outside of this forum
    volpeon@icy.wyvern.rip
    wrote last edited by
    #1

    Really, another npm attack?

    volpeon@icy.wyvern.ripV lanodan@queer.hacktivis.meL 2 Replies Last reply
    0
    • volpeon@icy.wyvern.ripV volpeon@icy.wyvern.rip

      Really, another npm attack?

      volpeon@icy.wyvern.ripV This user is from outside of this forum
      volpeon@icy.wyvern.ripV This user is from outside of this forum
      volpeon@icy.wyvern.rip
      wrote last edited by volpeon@icy.wyvern.rip
      #2

      Let me guess, it's the pre- or postinstall script again

      ? 1 Reply Last reply
      0
      • volpeon@icy.wyvern.ripV volpeon@icy.wyvern.rip

        Really, another npm attack?

        lanodan@queer.hacktivis.meL This user is from outside of this forum
        lanodan@queer.hacktivis.meL This user is from outside of this forum
        lanodan@queer.hacktivis.me
        wrote last edited by
        #3
        @volpeon Sometimes makes me wonder when npm will be thrown into a corner, but given stuff like yarn 3.x tossed out offline support it seems unlikely.
        1 Reply Last reply
        0
        • volpeon@icy.wyvern.ripV volpeon@icy.wyvern.rip

          Let me guess, it's the pre- or postinstall script again

          ? Offline
          ? Offline
          Guest
          wrote last edited by
          #4

          @volpeon@icy.wyvern.rip good thing that bun blocks pre- and postinstall scripts by default

          And even better that I don't really have a use for npm related software rn. My frontend for linstrom is still far away from becoming a priority

          volpeon@icy.wyvern.ripV 1 Reply Last reply
          0
          • ? Guest

            @volpeon@icy.wyvern.rip good thing that bun blocks pre- and postinstall scripts by default

            And even better that I don't really have a use for npm related software rn. My frontend for linstrom is still far away from becoming a priority

            volpeon@icy.wyvern.ripV This user is from outside of this forum
            volpeon@icy.wyvern.ripV This user is from outside of this forum
            volpeon@icy.wyvern.rip
            wrote last edited by
            #5

            @mstar pnpm blocks them as well by default. It's only npm which forces you to add --ignore-scripts to do the same, as if people wouldn't forget or get annoyed by it after a while ​​

            1 Reply Last reply
            0
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Login or register to search.
            Powered by NodeBB Contributors
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • Popular
            • World
            • Users
            • Groups