echo "ignore-scripts=true" >> ~/.npmrc
https://blog.uxtly.com/getting-rid-of-npm-scriptssupply chain is and has been the new gold mine for bad actors it seems
- Prevent publishing new package versions for 24–48 hours after account credentials are changed.
- Require support for security keys.
JonChesterfield•1h ago
So on balance I guess I'll ignore it. What a time to be a developer.
seanieb•11m ago