Hacker News new | ask | show | jobs
by beart 4 days ago
Does the allow list in package.json pin to the package version, or only to the package name?