Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
This package has a lot of transient dependencies, resulting in considerable supply chain risk. By pinning its version, we can ensure its dependencies won‘t be updated until we manually update cspell, which should be done through a pull request, so Socket.dev can alert us of malicious packages and other security vulnerabilities. Note that version pinning is only effective when cspell is installed with a lockfile.
- Loading branch information