Show HN: Safe-install – safer NPM installs with trusted build dependencies

gkiely 12 points 1 comment May 12, 2026
www.npmjs.com · View on Hacker News

In light of the ongoing npm supply chain compromises, I built safe-install: https://www.npmjs.com/package/@gkiely/safe-install It brings a couple of protections I wanted from npm but are not built in. Similar to Bun’s trusted dependencies, it lets you disable install scripts by default and define a list of dependencies that are allowed to run build/install scripts: https://bun.com/docs/guides/install/trusted It also supports blocking exotic sub-dependencies, similar to pnpm’s `blockExoticSubdeps` setting: https://gajus.com/blog/3-pnpm-settings-to-protect-yourself-f... I was hoping npm would eventually add something like this, but it does not seem to be happening soon, so I made a small package for it.

Discussion Highlights (1 comments)

edoceo

Yet again I'm asking folk to look at this artifact mirror that was Show HN a few months ago. https://github.com/artifact-keeper It's currently my favourite package gate keeper - after a few years of self-built jank

Semantic search powered by Rivestack pgvector
8,303 stories · 78,303 chunks indexed