4 ms·
Is there a way to configure npm that it only installs packages that are, like, a week old?
by ptrl600 1y ago
Is there a way to configure npm that it only installs packages that are, like, a week old?
- HatchedLake721 1y agoDon’t auto install latest versions, pick a version up to a patch and use package-lock.json
- mdaniel 1y agoThat's only half the story, as I learned yesterday <https://news.ycombinator.com/item?id=45172213 https://news.ycombinator.com/item?id=45172213> since even with lock files one must change the verb given to npm/yarn to have them honor the lock file So, regrettably, we're back to "train users" and all the pitfalls that entails
- 3np 1y agoMore importantly, avoid yarn[0] if you have a choice. They do not have a security posture fitting for 2025. There's way too much assumptions like "helpful" "magic" guessing/inferring what the user "actually wants" to "make things just work". See also: corepack. [0]: legacy 1.x projects aside
- feross 1y agoDisclosure: I’m the founder of https://socket.dev https://socket.dev A week waiting period would not be enough. On average, npm malware lingers on the registry for 209 days before it's finally reported and removed. Source: https://arxiv.org/abs/2005.09535 https://arxiv.org/abs/2005.09535
- ptrl600 1y agoOK, a week for popular packages, anything else I'd manually review each update. It'd be a nice feature.