Skip to content

v0.6.1

Choose a tag to compare

@dannote dannote released this 12 May 11:35
· 38 commits to master since this release
  • Harden tarball extraction against path traversal and absolute-path entries
  • Preserve install-script metadata in npm.lock
  • Warn when dependencies declare ignored lifecycle scripts
  • Document that npm_ex does not run package lifecycle hooks automatically, mitigating install-time credential stealers