Skip to content

Could you please disable by default scarf/scarf or remove at all #515

Answered by aviaviavi
Mavrin asked this question in General
Discussion options

You must be logged in to vote

Hi @Mavrin, author of @scarf/scarf here!

You are using "@scarf/scarf": "^1.0.0", with not exact version. What is happen if library was compromised.

This is true that react-query is not pinning to exact versions here, but that's the case for all of its dependencies and is also common practice for libraries. This allows upstream dependencies to make backward-compatible changes, especially those that could fix security issues if they are found. The concern you're raising is fair - It's always a good idea to know about your transitive dependencies and be aware of their risk profiles. The question of "what if a package is compromised?" applies to all dependencies and ultimately is a call tha…

Replies: 3 comments 5 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
4 replies
@Mavrin
Comment options

@aviaviavi
Comment options

@Mavrin
Comment options

@aviaviavi
Comment options

Answer selected by tannerlinsley
Comment options

You must be logged in to vote
1 reply
@aviaviavi
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
4 participants