logoalt Hacker News

jadaryesterday at 2:27 PM1 replyview on HN

It almost doesn't matter, because you can get pwned by a transitive dependency. If someone doesn't have the same scruples as you have, you're still at risk.


Replies

inbx0yesterday at 5:30 PM

minimumReleaseAge and lockfiles also pin down transitive dependencies.