Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add npm-shrinkwrap.json to restricted-files #2627

Merged
merged 1 commit into from Jun 13, 2022
Merged

Add npm-shrinkwrap.json to restricted-files #2627

merged 1 commit into from Jun 13, 2022

Conversation

oh2fih
Copy link
Contributor

@oh2fih oh2fih commented Jun 13, 2022

Just like the package.json & package-lock.json already on the restricted files list, the npm-shrinkwrap.json (publishable version of package-lock.json) also reveals the dependencies as well as the locked versions that are installed. It is publishable in the scope of a web application package, but should not be published with an installed web application.

@azurit
Copy link
Member

azurit commented Jun 13, 2022

Hi and thanks for this PR @oh2fih!

Looks good.

@dune73
Copy link
Member

dune73 commented Jun 13, 2022

Thank you for your contribution @oh2fih. Merging now.

@dune73 dune73 merged commit 0071f0c into coreruleset:v4.0/dev Jun 13, 2022
@oh2fih oh2fih deleted the oh2fih-npm-shrinkwrap branch June 13, 2022 13:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants