lirantal / lockfile-lint

Lint an npm or yarn lockfile to analyze and detect security issues
Apache License 2.0
782 stars 35 forks source link

Epic: enable fearless cooperation #124

Closed naugtur closed 1 year ago

naugtur commented 2 years ago

What's fearless cooperation? It's running 3rd-party code in a way you benefit from it but without risking anything worse than an error being thrown if it turns malicious.

Initial scope limited to lockfile-lint-api package

Changes proposed:

naugtur commented 2 years ago

@lirantal @JamesSingleton Wanna take a look?

Some finishing touches are missing (like docs/changelogs updates and a bit of rebasing) but the implementation seems done.

lirantal commented 2 years ago

Nice work, thanks for bringing this up.

lirantal commented 1 year ago

Looks like we're good here so I'm closing the issue.