Wouldn't this just make the number of packages that can be targeted smaller? E.g. I publish a testrunner that needs to install Headless Chrome if not present via postinstall. People trust me and put the package on their allowlist. My account gets compromised and a malicious update is published. People execute malicious code they have never vetted.I do understand this is still better than npm right now, but it's still broken.
acdha|1 month ago
jonkoops|1 month ago