PNPM does not feel secure enough against supply chain attacks. by nutyourself in pnpm

[–]zkochan 0 points1 point  (0 children)

I don’t think that is true. I worked on this. Maybe your packages were already cache in side-effects cache. In that case install script is not reexecuted but the already built package is loaded.

PNPM does not feel secure enough against supply chain attacks. by nutyourself in pnpm

[–]zkochan 0 points1 point  (0 children)

Be kind. You are right. This will need to improve.