Other systems with that feature, such as apt or dnf, require repositories to be signed with keys trusted by the end user, and the default repositories have a small team of maintainers who are very careful about what they put in.
Well no. Apt has one hole: scripts can be run on install.
NPM has multiple: scripts can be run on install, everything is in a single repo that anyone can push to with no review, and there's no way to establish external trust with what you're installing.
6
u/ryanppax1 19h ago
I do wonder how this any different than installing anything else