Replies: 1 comment
-
|
No feedback? Team isn’t interested in this? |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Which project does this relate to?
Router
Describe the bug
Context: I make security-focused NPM packages, with more downloads than tanstack-router. I've been trying to improve state of the ecosystem for 7 years, by reducing amount & size of deps.
When pull requests like #7430 are created, it feels odd. There are tens of dependency updates. How would you know that some of them weren't hacked? How do you know a new malware hadn't been added? Also, why is it necessary to always upgrade packages?
The idea is to:
^7.28.5. Instead,7.28.5should be used. This will ensure auto-upgrades won't happen automaticallyComplete minimal reproducer
https://example.com
Beta Was this translation helpful? Give feedback.
All reactions