blogs.social
Sign in
Home Top Authors Stats
🔥 Trending Latest
Andrew Nesbitt [Unofficial] @nesbitt.io.web.brid.gy
Jun 5
Install-script allowlists

In most package managers a dependency’s install-time code runs by default the moment you install it: an npm postinstall, a Setuptools setup.py, a CPAN Makefile.PL, an RPM scriptlet, a Conda post-link, a Debian postinst. A handful require explicit per-package opt-in before any of that code runs, usually called an allowlist or a trusted-dependencies list depending on the tool.

Per-package…

Read more →
♡
nesbitt.io 11.10.0npm approve-scriptsnpm deny-scripts
Page 1
🔥 Popular
What is Standard Site, and why is it useful?
@leaflet.pub · ♥ 18 · ↗ 5
japanese verb conjugation the simple hard way
@danabra.mov · ♥ 2 · ↗ 14
Incident Report: CVE-2026-LGTM
@andrewnez.bsky.social · ♥ 0 · ↗ 10
Reading Proposal 0016: What atproto’s “Permissioned Data” Actually Does
@ngerakines.me · ♥ 8 · ↗ 1
Can we billionaire-proof inference?
@graze.social · ♥ 7 · ↗ 2
Atmosphere Field Reporter Corps
@leaflet.pub · ♥ 7 · ↗ 1
📌 Trending tags
#chart 58 #weekly 55 #song 44 #Allgemein 20 #album 14 #Summer 12 #Ghyll 12 #Walking 12 #H01M10/0525 11 #LG ENERGY SOLUTION, LTD. 10 #TOYOTA JIDOSHA KABUSHIKI KAISHA 8 #CONTEMPORARY AMPEREX TECHNOLOGY CO., LIMITED 8 #H01M10/425 7 #Brott 6 #cv 6 #LG Energy Solution, Ltd. 6 #ai 6 #Hyundai Motor Company 6 #Web 6 #H01M10/613 5