4 ms·
It won't protect against a newer version of an established library introducing malicious behaviour.
by try_again 7y ago
It won't protect against a newer version of an established library introducing malicious behaviour.
- bluehatbrit 7y agoThis is correct, the few dependencies you would use would need to also target very specific versions to achieve the same. Lock files are used to lock dependency versions all the way down your dependency tree, not just your immediate dependencies.
- fpereiro 7y agoUnfortunately this seems to be the case; lockfiles would be unnecessary only if all your dependencies (and their dependencies, recursively all the way down) reference explicit versions, the risk being that a new malicious version would be published. I'll research if there's a workaround. Thanks everyone for pointing out this issue.
- bluehatbrit 7y agoIn my opinion a lock file really is the "work around", I don't see a huge issue in using them since it's given for free by npm and yarn with no additional overhead.