-
Notifications
You must be signed in to change notification settings - Fork 27
Open
Description
For example, I noticed there're two jsonc related dependencies:
Line 34 in a1930bf
| "jsonc-parser": "^3.2.0" |
Line 46 in a1930bf
| "jsonc": "^2.0.0", |
The one in the devDependencies was published 5 years ago, and maintained by 1 developer.
I know it's not been used in the source code yet, but I'm curious about how the supply chain security works there.
Thanks :)
Metadata
Metadata
Assignees
Labels
No labels