openemr / oe-schematron-service

0 stars 0 forks source link

Pin Node Dependencies to prevent supply chain attacks. #4

Closed adunsulag closed 2 years ago

adunsulag commented 2 years ago

We need to pin our node dependencies to mitigate supply chain attacks. Our own internal packages we will leave alone, but any external dependency we will pin the version.