Oh right, I can avoid the full isTrue library implementation with its 8000 dependencies, and instead install the isTrue client, which uses the isTrue cloud service and its REST APIs. Soon it will be AI powered. Then I’ll really be able to tell for sure if my variable value is actually true or not.
I only do npm install in a docker container where the project and npm cache is mounted. Gives me a bit of security regarding attacks through post install scripts. (--no-scripts is not an option since I need some of them)
When do people ever do npm install if you don't trust the project or know what install scripts will run? I'm a web developer of 10 years and I've never run npm install to install a piece of software. The only time I ever run npm is when I'm doing development for work.
Usually in the "lets see how this random project I cloned from GitHub works for my use case" scenario. I want to see how it works and if it would cover my use case before spending time on checking code and dependencies for security issues.
14 Comments
GottaHaveFaith@fedia.io · 63 pts · 267d
Installed 4239 packages 8000 severe vulnerabilities 200 packages looking for funding
jaybone@lemmy.zip · 16 pts · 267d
But how else will I figure out if a value is true?
marius@feddit.org · 14 pts · 267d
I bet there's an online service for that
jaybone@lemmy.zip · 22 pts · 267d
Oh right, I can avoid the full isTrue library implementation with its 8000 dependencies, and instead install the isTrue client, which uses the isTrue cloud service and its REST APIs. Soon it will be AI powered. Then I’ll really be able to tell for sure if my variable value is actually true or not.
Nomecks@lemmy.ca · 4 pts · 267d
You just call GPT and ask if it's true. Get with the times!
vrek@programming.dev · 3 pts · 267d
Look, can I ask a favor? Can you take that, package it, and put it on npm so I can use it in my project?
StopSpazzing@lemmy.world · 19 pts · 268d
Jayden animations?
dbx12@programming.dev · 12 pts · 268d
I only do npm install in a docker container where the project and npm cache is mounted. Gives me a bit of security regarding attacks through post install scripts. (
--no-scriptsis not an option since I need some of them)victorz@lemmy.world · 2 pts · 267d
When do people ever do npm install if you don't trust the project or know what install scripts will run? I'm a web developer of 10 years and I've never run npm install to install a piece of software. The only time I ever run npm is when I'm doing development for work.
dbx12@programming.dev · 1 pts · 266d
Usually in the "lets see how this random project I cloned from GitHub works for my use case" scenario. I want to see how it works and if it would cover my use case before spending time on checking code and dependencies for security issues.
victorz@lemmy.world · 1 pts · 266d
So it doesn't have any other means of installing I take it.
Usually I take that as a red flag, that it isn't popular or mature enough. But to each their own.
oopsallnaps@piefed.ca · 6 pts · 267d
always close your toilet lid before npm installing!
hacktheegg@programming.dev · 3 pts · 266d
Run the commands and ignore all of the outputs
Nothing could go wrong :)
Thedogdrinkscoffee@lemmy.ca · 3 pts · 267d
Forgot to make a salt circle to contain the evil.