Skip to content

Conversation

dominik-bln
Copy link

Add package-lock.json to ensure exact versions as recommended:

https://docs.npmjs.com/files/package-lock.json#description

@kimmobrunfeldt
Copy link
Member

Hi! Thanks for the effort, this is definitely a good change. For security reasons, I'll do this package-lock.json file myself because it's really hard to review the whole file and I don't know exactly the implications of what could be done by adding a small malicious package in package-lock.json. I'm not saying you would ever do this, but it's better to be cautious. Hope you understand.

@dominik-bln
Copy link
Author

Totally understandable and updating is probably not bad anyways by now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants