Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The package-lock.json includes a hash of the package, not just a version number which should be immutable.


To add to this: the hash in the lock file is the checksum of the published tarball, not the commit hash.


And then someone runs `npm install` on their CI




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: