AIBoxPro搜索工具
AI 资讯/Show HN: Safe-install – safer NPM installs with trusted build dependencies
AI公司动态2026年5月12日 00:30来源:Hacker News

Show HN: Safe-install – safer NPM installs with trusted build dependencies

快速了解

<p>In light of the ongoing npm supply chain compromises, I built safe-install:<p><a href="https://www.npmjs.com/package/@gkiely/safe-install" rel="nofollow">https://www.npmjs.com/package/@gkiely/safe-install</a><p>It brings a couple of protections I wanted from npm but are not built in.<p>Similar to Bun’s trusted dependencies, it lets you disable install scripts by default and define a list of dependencies that are allowed to run build/install scripts:<p><a href="https://bun.com/docs/guides/install/trusted" rel="nofollow">https://bun.com/docs/guides/install/trusted</a><p>It also supports blocking exotic sub-dependencies, similar to pnpm’s `blockExoticSubdeps` setting:<p><a href="https://gajus.com/blog/3-pnpm-settings-to-protect-yourself-from-supply-chain-attacks#2-set-blockexoticsubdeps" rel="nofollow">https://gajus.com/blog/3-pnpm-settings-to-protect-yourself-f...</a><p>I was hoping npm would eventually add something like this, but it does not seem to be happening soon, so I made a small package for it.</p> <hr> <p>Comments URL: <a href="https://news.ycombinator.com/item?id=48102636">https://news.ycombinator.com/item?id=48102636</a></p> <p>Points: 10</p> <p># Comments: 0</p>

🔗 延伸阅读

阅读原文
Hacker News
分享给朋友

📰 你可能也感兴趣

靠AI把股价干涨735%,这家公司开始成批裁掉可替代岗,全员招聘须CEO点头

AI公司动态2026年5月11日 15:54

OpenAI校园网络:学生社团兴趣表

AI公司动态2026年5月11日 10:00

波兰电商平台Allegro与OpenAI达成合作,将生成式AI引入购物体验

AI公司动态2026年5月11日 09:19

2500亿美元的xAI死了,但SpaceXAI的算力游戏才刚开始

AI公司动态2026年5月11日 03:14

摩根大通再次上调韩国Kospi指数目标位,称存储芯片周期等因素构成利好

AI公司动态2026年5月11日 03:08