this post was submitted on 09 Nov 2025
283 points (99.0% liked)
Programmer Humor
27248 readers
860 users here now
Welcome to Programmer Humor!
This is a place where you can post jokes, memes, humor, etc. related to programming!
For sharing awful code theres also Programming Horror.
Rules
- Keep content in english
- No advertisements
- Posts must be related to programming or programmer topics
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I only do npm install in a docker container where the project and npm cache is mounted. Gives me a bit of security regarding attacks through post install scripts. (
--no-scriptsis not an option since I need some of them)When do people ever do npm install if you don't trust the project or know what install scripts will run? I'm a web developer of 10 years and I've never run npm install to install a piece of software. The only time I ever run npm is when I'm doing development for work.