Skip to content

Conversation

@rmgpinto
Copy link
Contributor

@rmgpinto rmgpinto commented Dec 1, 2025

ref https://linear.app/ghost/issue/PRO-1540/

  • there have been multiple recent npm incidents with compromised packages using pre/post-install scripts to run malicious scripts
  • we want to default to not running these scripts as a security precaution, this matches behaviour of pnpm which is touted as a modern, more secure, npm package manager

ref https://linear.app/ghost/issue/PRO-1540/

- there have been multiple recent npm incidents with compromised
packages using pre/post-install scripts to run malicious scripts
- we want to default to not running these scripts as a security
precaution, this matches behaviour of pnpm which is touted as a modern,
more secure, npm package manager
@rmgpinto rmgpinto merged commit cbde1f3 into main Dec 1, 2025
1 check failed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants