pnpm 10 turned off implicit postinstall in npm dependencies, and it is very good for security.
And at BlueSky, the Yarn team announced that they're going to do the same.
https://bsky.app/profile/yarnpkg.dev/post/3lelyznjs422j
=> More informations about this toot | More toots from sitnik_en@mastodon.social
text/gemini
This content has been proxied by September (ba2dc).