Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
what
1mo ago
0 comments
Share
Pinning doesn’t help you. They can replace the package and you’ll get the new one. You have to vendor the dependencies.
0 comments
default
newest
oldest
botch_san
1mo ago
Pinning the SHA package hash would help? I am not too familiar with Python dependency management, so not sure if this is supported.
davidatbu
1mo ago
I don't think pypi or npm allow replacing existing packages?
1 more reply
j
/
k
navigate · click thread line to collapse