Skip to content
This repository has been archived by the owner on May 17, 2024. It is now read-only.

Address security alert #67

Merged
merged 2 commits into from
Apr 24, 2019
Merged

Address security alert #67

merged 2 commits into from
Apr 24, 2019

Conversation

FokkeZB
Copy link
Contributor

@FokkeZB FokkeZB commented Apr 23, 2019

See https://github.com/zapier/zapier-platform-schema/network/alerts

As part of my T3 I thought I'd address some of these in my mailbox.

@FokkeZB FokkeZB self-assigned this Apr 23, 2019
@FokkeZB FokkeZB requested a review from xavdid April 23, 2019 12:38
Copy link
Contributor

@xavdid xavdid left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

approving as not to block you, but I strongly suggest requiring an exact version before merging.

package.json Outdated Show resolved Hide resolved
@FokkeZB FokkeZB merged commit 24de969 into master Apr 24, 2019
@FokkeZB FokkeZB deleted the fix-alerts branch April 24, 2019 08:06
@xavdid
Copy link
Contributor

xavdid commented Apr 24, 2019

The lockfile ensures developers all work with the same version, but the lockfile isn't published to the end-user. Info here: https://docs.npmjs.com/files/package-lock.json

@FokkeZB
Copy link
Contributor Author

FokkeZB commented Apr 24, 2019

O wow, I always thought it guaranteed dependencies for end-user installs as well! I see that's what shrinkwrap does.

I see the same is true for yarn.lock and they actually explain why very well at:
https://yarnpkg.com/blog/2016/11/24/lockfiles-for-all/

First, it’s not going to be every user that is affected by this. It’s well agreed upon that applications should be using lockfiles, and if they are then they won’t be affected by sudden breaking changes.

TOL!

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants