4 ms·
A console.log in your npm package post-install is an attack vector? Sure, there are many nasty things you could do in a packages post-install, I think a text ba
by whyrusleeping 7y ago
A console.log in your npm package post-install is an attack vector? Sure, there are many nasty things you could do in a packages post-install, I think a text based ad is the least of your concerns.
- zzo38computer 7y agoIt probably is the least of the concerns, although still it is one thing. (However, note there is a --ignore-scripts switch. There is also --no-optional, but I don't know how commonly such thing is in use that it would help; it would need to be marked as a optional dependency for --no-optional to work, probably. And then, there is also --dry-run.)