Skip to content

Did all dependencies been reviewed for security? #213

@hellodword

Description

@hellodword

For example, I noticed there're two jsonc related dependencies:

"jsonc-parser": "^3.2.0"

"jsonc": "^2.0.0",

The one in the devDependencies was published 5 years ago, and maintained by 1 developer.

I know it's not been used in the source code yet, but I'm curious about how the supply chain security works there.

Thanks :)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions