Issue #3277025 by Spokje, longwave: For additional security you should declare the allow-plugins config with a list of packages names that are allowed to run code
mentioned in commit 73d0a0c1
mentioned in commit d1721377