Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
mcintyre1994
81 days ago
|
parent
|
context
|
favorite
| on:
GitLab discovers widespread NPM supply chain attac...
In this narrow case, using pnpm or something similar that blocks postinstall scripts by default should be sufficient. In general, you probably want to use a container/vm/sandbox of some sort so dev stuff can’t access anything else on your machine.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: