Honestly, I'm strongly considering moving away from the NPM ecosystem because it's clearly become a target for malware.
Honestly, I'm strongly considering moving away from the NPM ecosystem because it's clearly become a target for malware.
Edit: if anyone knows of a way to disable NPM from running install scripts automatically (without having to remember to specify --ignore-scripts on each invocation), while still allowing me to use "npm run" to manually run scripts (e.g. test scripts for my own packages), I'd love to hear about it.
npm config set ignore-scripts true
which will update ~/.npmrc (you can also create project-specific .npmrc files if you prefer)You can see how NPM has been configured by running
npm config list npm help run-script
[...]
ignore-scripts
o Default: false
o Type: Boolean
If true, npm does not run scripts specified in package.json files.
Note that commands explicitly intended to run a particular script, such as npm
start, npm stop, npm restart, npm test, and npm run-script will still run their
intended script if ignore-scripts is set, but they will not run any pre- or
post-scripts.Trust. Why is it that random people can submit packages? Make it so they can't. Only trustworthy people should be able to do that. People who care, so that we don't have to. People we can trust. This is how Linux distributions work and you just don't see malware randomly making its way into official repositories.
These Debian wrappers, however minimal, imply the existence of a maintainer trusted by the Debian community. It's assumed that this maintainer has read the source code and determined it is safe.
E.g. "This is maintained by a huge network of contributors who contribute to other huge projects" vs "This is a single developer with a couple commits a year"
Uses the object capability model provided by SES [2].
[1] https://github.com/LavaMoat/LavaMoat [2] https://github.com/endojs/endo