You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I'd like to pin all our dependency versions. The pad-left debacle has confirmed something to me:
09:31 &YaManicKill Yeah, it might be fine because we don't use pinned versions (but...we probably should, now that I've thought about some things today)
09:31 &YaManicKill Because technically, someone can unpublish something, someone else can then take that name and publish new code with a patch version number update, and include malicious code.
The text was updated successfully, but these errors were encountered:
That can be run to find out if any of our packages were one of the ones pulled btw, and then we can check we won't download a new "malicious" version of it.
I'd like to pin all our dependency versions. The pad-left debacle has confirmed something to me:
The text was updated successfully, but these errors were encountered: