@linusgsebastian@IrlLillie Iโm well aware, it was meant as a joke because itโs still seen as a Canadian brand despite being owned by Brazilians lol
Today is another package-lock.json appreciation day!
- Make sure you always commit your project with the package-lock.json file. It is the ONLY version locking enforcement mechanism.
- Use npm ci instead of npm install. The first one will work ONLY if package-lock.json exists.
- If you need to update or pull new packages, use the --min-release-age flag (available since npm v11.10.0) to make sure you only install updates, which are at least 7 days old:
npm install --min-release-age=7
Or hardcode this setting into your .npmrc file:
min-release-age=7
There will be more malicious updates to popular npm packages in the future, driven by supply chain attacks. It's just the beginning.
Thankfully, they will be caught in the first 24 hours.
The npm ecosystem is broken by design.
Adapt and act accordingly.
Stay safe out there!
Been using the @belairdirect auto merit and I cannot seem to get the smoothness up. My braking is borderline limo quality, super smooth. And I donโt think I accelerate too fast at all compared to people around me. Is there something Iโm missing?
Still no fix however for weather alerts in Canada. Getting alerts for areas 100โs of kilometres away. Iโve reported this issue over email on the 17th of February and never got a reply from @CARROT_app about whether this is something they will fix or not.
CARROT Weather 6.4 is now available, meatbags! New data source (The Weather Channel), realistic weather effects, NWS area forecast discussions, Weather Underground stations, customizable Apple Watch app backgrounds, and more. Update nowโฆ or else. https://t.co/cfh5hKHfz3