Skip to content

Pin dependencies to exact versions #493

@bdresser

Description

@bdresser

Both Gaba and MetaMask each contain over 1000 dependencies, most of which are not pinned to an
exact version but set to compatible version (^x.x.x). This can potentially enable dependency attacks as
observed with the event-stream package with the Copay Bitcoin Wallet.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions