mirror of
https://github.com/GSA/notifications-admin.git
synced 2026-02-05 19:03:30 -05:00
This means we can use tools like "npm audit" to look for security vulnerabilities we definitely need to fix as they could pose a direct risk to users. I've checked each of them with @tombye and also against an external set of principles [^1]. Note: I've skimmed through the package-lock.json to check the only changes are to add "dev: true", as well as a few integrity hashes. [^1]: https://betterprogramming.pub/is-this-a-dependency-or-a-devdependency-678e04a55a5c
1.7 KiB
1.7 KiB