On Tue, Oct 5, 2021 at 12:29 PM Konrad Weihmann <kweihm...@outlook.com>
wrote:

>
> While personally I think in the long run, every npm dependency has to be
> provided as a recipe of its own (even I know the costs of that pretty
> well)... esp when CVE checking and basic packaging hygiene should be
> enforced.
>

Emphatically agree. The "stuff it all into one recipe" npm approach is very
broken.

..Ch:W..


-- 
*"Perfection must be reached by degrees; she requires the slow hand of
time." - Voltaire*
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#156672): 
https://lists.openembedded.org/g/openembedded-core/message/156672
Mute This Topic: https://lists.openembedded.org/mt/86089523/21656
Group Owner: openembedded-core+ow...@lists.openembedded.org
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to