https://aube.en.dev/package-manager/jailed-builds.html
But this feels like a cat/mouse game.
https://aube.en.dev/package-manager/jailed-builds.html
But this feels like a cat/mouse game.
1. It seems like the restrictions are only for lifecycle scripts, so wouldn't help if/when the package's actual code had malicious code inserted?
2. Package managers like pnpm seem to entirely block lifecycle scripts by default, so I guess this is an in-between solution.
Still, I guess it's a step in the right direction for those want or need to run lifecycle scripts specifically.
2. aube does the same. This is an extra level of protection if you've already whitelisted a package
That is what made Bun popular, and tools like uv/pip, oxlint/eslint, orbstack/docker desktop, and the list goes on. Drop-in replacements where we get 10x with little effort.