Changelog Master Feed cover image

Securing npm is table stakes (Changelog Interviews #674)

Changelog Master Feed

00:00

Why pre/post-install scripts are dangerous

Nicholas explains how install scripts let packages execute arbitrary code and why they enable many attacks.

Play episode from 37:54
Transcript

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app