Synthetixio / issues

0 stars 3 forks source link

get rid of direct reference to github.com for dependencies at synthetix repo #337

Closed drptbl closed 2 years ago

drptbl commented 2 years ago

Why? To increase security of our repository while installing deps by disallowing github.com host from lockfile-linter.

Affected dependency:

Solved with patch-package dependency (could also be solved by publishing it from our own account on npm).

Related PR: https://github.com/Synthetixio/synthetix/pull/1517