Skip to content

pin dependencies#40

Open
munrocket wants to merge 1 commit intotheQRL:mainfrom
munrocket:pin
Open

pin dependencies#40
munrocket wants to merge 1 commit intotheQRL:mainfrom
munrocket:pin

Conversation

@munrocket
Copy link

@munrocket munrocket commented Feb 4, 2026

We all tired of npm supply chain attacks. Let's pin dependencies and update it with npx npm-check-updates -u .

Refs:
https://unit42.paloaltonetworks.com/npm-supply-chain-attack/
https://trustwallet.com/blog/announcements/trust-wallet-browser-extension-v268-incident-community-update

@jplomas
Copy link
Contributor

jplomas commented Feb 4, 2026

Thank you for your PR. While this has been roadmapped for final release, given the maturity of this codebase I have no issues with this defence-in-depth once the tests pass (lockfile needs committing). Feel free to update PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants