🎊 npm v12 blocks postinstall scripts by default
You should celebrate ) even if you don't use npm
Surprisingly, this also improves supply chain security for pnpm, Yarn, Bun and other ecosystems such as PyPi
=> it reduces the ability for npm / multi-ecosystem worms to spread
JS devs - Time to celebrate 🎊 🥂
All modern package managers will block postinstall scripts by default :
📦 npm v12 🆕
📦 pnpm 10
📦 Yarn 4.14
📦 Bun
📦 Deno
📦 Aube
This doesn't solve everything, but should greatly reduces the ability for supply chain worms to spread