3 ms·
iirc does pnpm not allow them by default. But even if we killed them off there would still be a chance of the malware hooking into something else or only workin
by mechazawa 2mo ago
iirc does pnpm not allow them by default. But even if we killed them off there would still be a chance of the malware hooking into something else or only working in cli applications.
- jonchurch_ 2mo agonpm v12 released last month also defaults into blocking them by default
- madeofpalk 2mo agoThe latest version of all node package managers (npm, yarn, pnpm) now deny this by default. pnpm was ahead of the curve.