• style99@kbin.social
    link
    fedilink
    arrow-up
    5
    ·
    1 year ago

    Examine dependencies and installation scripts. Very recently published, net-new packages, or scripts or dependencies that make network connections during installation should receive extra scrutiny.

    I’m a little surprised npm doesn’t already do this and give you a big blinking warning in the install process about it.