Bun added `trustedDependencies` [1] to package.json and only executes postInstall scripts coming from these dependencies. I think this is something that should be supported across all JS package managers, even more than version cooldowns.
Having trusted dependencies at least drastically reduces the risk that 'git clone && npm install' takes over the entire system.
Cooling down dependencies would certainly help, also.