Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
mechazawa
52 days ago
|
parent
|
context
|
favorite
| on:
Keyv and friends compromised in active Shai-Hulud ...
iirc does pnpm not allow them by default. But even if we killed them off there would still be a chance of the malware hooking into something else or only working in cli applications.
madeofpalk
52 days ago
|
next
[–]
The latest version of all node package managers (npm, yarn, pnpm) now deny this by default. pnpm was ahead of the curve.
jonchurch_
52 days ago
|
prev
[–]
npm v12 released last month also defaults into blocking them by default
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: