JS devs - Time to celebrate 🎊 🥂
All modern package managers will block postinstall scripts by default :
📦 npm v12 🆕
📦 pnpm 10
📦 Yarn 4.14
📦 Bun
📦 Deno
📦 Aube
This doesn't solve everything, but should greatly reduces the ability for supply chain worms to spread