Skip to content

trusted dependenciesΒ #8573

@gkiely

Description

@gkiely

What is the problem this feature will solve?
Arbitrary npm scripts being run on postinstall without the developers knowledge.

What is the feature you are proposing to solve the problem?
In light of the recent npm attacks, it would be great to support something similar to bun's trustedDependencies.

This allows a list the most popular dependencies to run on postinstall and requires defining an array of additional dependencies to run in trustedDependencies.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions