|
|
|
|
|
by nulltrace
59 days ago
|
|
Lockfiles help more than people realize. If you're pinned and not auto-updating deps, a package getting sold and backdoored won't hit you until you actually update. The scarier case is Dependabot opening a "patch bump" PR that probably gets merged because everyone ignores minor version bumps. |
|