-
-
Notifications
You must be signed in to change notification settings - Fork 67
Open
Labels
Description
Description
So this is trending causing hysteria and finger pointing.
- https://www.stepsecurity.io/blog/ctrl-tinycolor-and-40-npm-packages-compromised
- https://news.ycombinator.com/item?id=45260741
Something that came out of the comment thread was to limit updates to packages that are at least of a certain age.
What's the chance we can explore this for syncpack?
Suggested Solution
unsure?
Optional comments
No response
Code of Conduct
- I agree to follow the Code of Conduct