Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

pnpm does all that on top of node. Also disables postinstall scripts by default, making the recent security incidents we've seen a non-issue.


As the victim of the larger pre-Shai-Hulud attack, unfortunately the install script validation wouldn't have protected you. Also, if you already have an infected package on the whitelist, a new infection in the install script will still affect you.


I’m not sure why but bun still feels snappier.



Aside from speed, what would the major selling points be on migrating from pnpm to bun?


Are there any popular packages that require postinstall scripts that this hurts?


A whitelist in package.json is only a partial assist




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: