4 ms·
I'm not aware of any security advantages compared to npm. But one thing that comes to mind is that a while ago npm, by default, did not generate lock files, whi
by MattyRad 8y ago
I'm not aware of any security advantages compared to npm. But one thing that comes to mind is that a while ago npm, by default, did not generate lock files, which is very much a risk concerning deployment and dependency-management in general. It's not an issue any longer, though, both yarn (yarn.lock) and npm (package-lock.json?) generate lock files by default.