In this scenario, if a dependency were to add a "postinstall" script because it was compromised, it would not execute, and the user can review whether it should, greatly reducing the attack surface.
I do understand this is still better than npm right now, but it's still broken.
> defending the mullahs wasn't exactly on my bingo card, but here we are...
Propaganda is a hell of a drug.