This package compiles itself on install and then shipped everything except the result.
With no explicit file list, npm falls back to .gitignore — and .gitignore excludes the build output. So the install hook ran, compiled the package, and npm then packed the sources and left the compiled directory behind. Every consumer received a package whose every entry point pointed at a directory that had just been built and then excluded.
The workaround for this lived in mesh-tools, which installed this package and then compiled it by hand, with a comment saying the hook "does not run". The hook runs. The output was being thrown away afterwards.
This package compiles itself on install and then shipped everything except the result.
With no explicit file list, npm falls back to `.gitignore` — and `.gitignore` excludes the build output. So the install hook ran, compiled the package, and npm then packed the sources and left the compiled directory behind. Every consumer received a package whose every entry point pointed at a directory that had just been built and then excluded.
The workaround for this lived in mesh-tools, which installed this package and then compiled it by hand, with a comment saying the hook "does not run". The hook runs. The output was being thrown away afterwards.
It compiles itself on install and then shipped everything except the result.
With no explicit file list npm falls back to .gitignore, which ignores dist —
so every consumer received a package whose every entry point pointed at a
directory that had just been built and then excluded.
The workaround for this lived in mesh-tools, which compiled the dependency by
hand after installing it.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This package compiles itself on install and then shipped everything except the result.
With no explicit file list, npm falls back to
.gitignore— and.gitignoreexcludes the build output. So the install hook ran, compiled the package, and npm then packed the sources and left the compiled directory behind. Every consumer received a package whose every entry point pointed at a directory that had just been built and then excluded.The workaround for this lived in mesh-tools, which installed this package and then compiled it by hand, with a comment saying the hook "does not run". The hook runs. The output was being thrown away afterwards.