v0.6.1
- Harden tarball extraction against path traversal and absolute-path entries
- Preserve install-script metadata in
npm.lock - Warn when dependencies declare ignored lifecycle scripts
- Document that
npm_exdoes not run package lifecycle hooks automatically, mitigating install-time credential stealers