getsentry / getsentry/sentry-javascript
Pin dependencies
Offen
Core
Type: Improvement
- Vorherrschende Sprache
- TypeScript
- Sterne
- 8.7k
- Forks
- 1.8k
- Ø Merge
- 1 T. 17 Std.
- Gemergte PRs (30 T.)
- 515
Beschreibung
### Description
We should start pinning all our dependencies more aggressively, given the recent supply chain attacks and other problems arising from bumping dependencies. Some things to consider
- latest/next/canary tests need to be excempt from pinning
- we keep some dependency versions `^`-declared on purpose so that users can potentially install more recent (minor/patch) versions of the package and deduplicate the installed version. This concerns our bundler plugins mostly. A couple of OTel packages have the same strategy. We should re-evaluate if this makes sense on a package-by-package level.
Beitragsleitfaden
Bewertung
Dieses Issue wurde noch nicht bewertet.