Skip to content

Migrate to pnpm#44

Open
livtanong wants to merge 2 commits into
mainfrom
pnpm
Open

Migrate to pnpm#44
livtanong wants to merge 2 commits into
mainfrom
pnpm

Conversation

@livtanong

Copy link
Copy Markdown
Collaborator

As you are no doubt aware, the npm supply chain has come under attack in recent memory. While it is impractical to inspect each package and its upstream dependencies one by one, there are some ways we can defend ourselves in efficient ways.

The most significant change in my opinion is a switch to pnpm, as it has made significant efforts towards mitigating supply chain attacks. For more information: https://pnpm.io/supply-chain-security

As an added benefit, pnpm is widely considered faster and more efficient than npm.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant