Lokasi ngalangkungan proxy:   [ UP ]  
[Ngawartoskeun bug]   [Panyetelan cookie]                
🚀. Socket Launch Week Day 3:Socket Firewall Now Blocks Malicious VS Code and Open VSX Extensions.Learn more →
Sign In

Missing lockfile

Severity

High

Short Description

A manifest file was found without a corresponding lockfile. Without a lockfile, dependency resolution is non-deterministic and may resolve to different (potentially malicious) versions across installs.

Suggestion

Add a lockfile (e.g. package-lock.json, yarn.lock, Gemfile.lock, poetry.lock) to your repository and commit it to version control. This ensures deterministic dependency resolution and protects against supply chain attacks.

Socket for GitHub

Socket Firewall

Socket CLI

Socket Certified Patches

Socket Web Extension

Socket Optimize

Socket Dependency Search

Socket Reachability

Languages

JavaScript / TypeScript

Stay in touch

Get open source security insights delivered straight into your inbox.

Book a DemoSign In

Made with ⚡️ by Socket Inc

U.S. Patent No. 12,346,443 & 12,314,394. Other pending.

SOC 2 Type II certified