Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

removing the line in dockerfile that does rm package-lock.json #742

Open
kevkevinpal opened this issue Aug 1, 2023 · 0 comments
Open

removing the line in dockerfile that does rm package-lock.json #742

kevkevinpal opened this issue Aug 1, 2023 · 0 comments
Labels
bug Something isn't working

Comments

@kevkevinpal
Copy link
Contributor

kevkevinpal commented Aug 1, 2023

This is a security concern because if a package that we use gets compromised and they replace the current version with mal intentioned software we/a user could be building a new docker image with a new package with same version number that is compromised

would like to add this is not the biggest of concerns but it is bad practice

@kevkevinpal kevkevinpal added the bug Something isn't working label Aug 1, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant