alt
Hacker News
baobun
•
yesterday at 8:18 AM
•
0 replies
•
view on HN
Just don't use actions which pull in arbitrary npm packages without a lockfile.