Skip to content

Conversation

@aduh95
Copy link
Contributor

@aduh95 aduh95 commented Dec 21, 2025

So we're less likely to hit any supply chain attack. Worth noting the only remaining dependency (gitlint-parser-node) has not seen any commit in the last 9 years, so it's very much stable at this point, and pinning it will almost certainly not add any maintenance burden.

Refs: https://docs.npmjs.com/cli/v11/configuring-npm/npm-shrinkwrap-json

@targos
Copy link
Member

targos commented Dec 21, 2025

The shrinkwrap file must be included in package.json#files to end up in the published package.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants