devcontainers / devcontainers/action
Did all dependencies been reviewed for security?
Open
- Dominant language
- TypeScript
- Stars
- 88
- Forks
- 32
- PR merge metrics
- No merged PRs in 30d
Description
For example, I noticed there're two jsonc related dependencies:
https://github.com/devcontainers/action/blob/a1930bf7eb60408bbfd6e201d88e33cdec41a25e/package.json#L34
https://github.com/devcontainers/action/blob/a1930bf7eb60408bbfd6e201d88e33cdec41a25e/package.json#L46
The one in the devDependencies was published 5 years ago, and maintained by 1 developer.
I know it's not been used in the source code yet, but I'm curious about how the supply chain security works there.
Thanks :)
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.