Use node js git security advisories instead of using npm registry - #228
Merged
pombredanne merged 3 commits intoJul 23, 2020
Merged
Conversation
pombredanne
approved these changes
Jul 23, 2020
pombredanne
left a comment
Member
There was a problem hiding this comment.
LGTM! ... I may wonder if using a direct download instead of a git checkout may have been simpler... but that's a small thing
Member
|
Please rebase and I will mereg |
Collaborator
Author
Good question. Thing is |
Signed-off-by: Shivam Sandbhor <shivam.sandbhor@gmail.com>
Signed-off-by: Shivam Sandbhor <shivam.sandbhor@gmail.com>
Signed-off-by: Shivam Sandbhor <shivam.sandbhor@gmail.com>
sbs2001
force-pushed
the
use_nodejs_git_repo_for_npm_importer
branch
from
July 23, 2020 12:18
827f52e to
66f55f8
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR switches the NPM importer to use https://github.com/nodejs/security-wg instead of https://registry.npmjs.org/-/npm/v1/security/advisories
Reasons :
https://registry.npmjs.org/-/npm/v1/security/advisories has given trouble to us in past, recently it was down for some time. The git data source is way more robust.
We also get to use GitDataSource which has alot of goodies.
https://github.com/nodejs/security-wg is the upstream
Signed-off-by: Shivam Sandbhor shivam.sandbhor@gmail.com