logoalt Hacker News

flerchintoday at 4:16 PM1 replyview on HN

Ok it's bad, but our npm projects are pinned in the package-lock.json, which I imagine most would be? So who would pull this besides security scanners?


Replies

croemertoday at 4:17 PM

`npm install` might be enough to pull it, unless you pin down to the patch?

show 1 reply