The Changelog: Software Development, Open Source cover image

Securing npm is table stakes (Interview)

The Changelog: Software Development, Open Source

00:00

Risks of pre/post-install scripts

Nicholas explains how install scripts enable arbitrary code execution and why they're dangerous for public registries.

Play episode from 37:54
Transcript

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app