Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add lockfile-lint to check for bad errors in yarn.lock #2278

Merged
merged 2 commits into from Oct 21, 2019

Commits on Oct 14, 2019

  1. Add lockfile-lint to check for bad errors in yarn.lock

    The article [1] describes possible attacks that can be conveyed using
    yarn.lock. This tool lockfile-lint helps avoid common threats.
    
    [1] https://snyk.io/blog/why-npm-lockfiles-can-be-a-security-blindspot-for-injecting-malicious-modules/
    julienw committed Oct 14, 2019
    Configuration menu
    Copy the full SHA
    c72d45a View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    74f9ccf View commit details
    Browse the repository at this point in the history