-
Notifications
You must be signed in to change notification settings - Fork 944
Open
Labels
Description
Problem Description
To minimize security vulnerabilities, enabling Dependabot, Renovate or another alternative for scheduled dependency updates would be useful.
Since the package-lock.json file is not published, there's no way to verify dependencies have the upgraded.
Potential Solution
Enable Dependabot, Renovate or another alternative for scheduled dependency updates to enhance security and outdated dependencies.
Snyk is another option that can be considered as a developer security platform to help identify vulnerabilities in dependencies.