| ▲ | martmulx 19 hours ago | ||||||||||||||||
Does pnpm block postinstall on transitive deps too or just top-level? We have it configured at work but I've never actually tested whether it catches scripts from packages that get pulled in as sub-dependencies. | |||||||||||||||||
| ▲ | arcfour 18 hours ago | parent | next [-] | ||||||||||||||||
It prompts for transitive dependencies, too. I have never had workerd as a direct dependency of any project of mine but I get prompted to approve its postinstall script whenever I install cloudflare's wrangler package (since workerd needs to download the appropriate Workers runtime for your platform). | |||||||||||||||||
| ▲ | dawnerd 19 hours ago | parent | prev [-] | ||||||||||||||||
From what I can tell, it blocks it everywhere. | |||||||||||||||||
| |||||||||||||||||