logoalt Hacker News

baobunyesterday at 8:18 AM0 repliesview on HN

Just don't use actions which pull in arbitrary npm packages without a lockfile.