ended6월 29일· 1 sources
CI is the wrong place to first hear about your npm dependencies
Why it matters
Your CI catches the npm vulnerability. Your developer is already three branches away and one standup behind. The package is installed, the lockfile regenerated, the import wired into a service, and th...
1
Sources
+0
24h
—
Growth
3d
Active