Skip to main content

Activity for finnbayer.de

Active on:

Loading activity...

While I agree with this take it should still be a set value in every current config just to make sure that every person gets the benefit. Even if persons use a version of a package manager that does not set a default (pnpm before v11, current Npm versions etc). Goal: default in pm + set config value

@notwes.bsky.social avatarWes@notwes.bsky.social

I will add a personal opinion: putting this config in every user repo is an asinine decision from a maintainability perspective. Secure defaults (which could include a delay until a package can be scanned before being available from the registry) is a much more scalable solution.

Bluesky network1mo ago
Link unavailable

Joined a Colibri community

3mhyddoabof2r

Colibri3mo ago

A lot has happened in the last two minor releases of the npm cli that is important to know for people using it: v11.9 : allow-git flag v11.10: min-release-age 🧵

Bluesky network3mo ago
Link unavailable

Did my first talk regarding npm supply chain attacks at an internal developer conference last week. 🎉 My main talking point: Pay attention. It is so easy to mindlessly run an npm install without thinking about possible consequences. 🧵

White male person presenting. He is pointing and looking at a screen which can’t be seen
Bluesky network3mo ago
Link unavailable
Activity - finnbayer.de | Sifa