ShuさんはTwitterを使っています: 「When reviewing PRs especially in open source projects, remember to also take a look at npm/yarn/pnpm lockfile changes. They can be used to attack the project by introducing malicious dependencies. Like this: https://t.co/20HjFYRGWS」 / Twitter https://twitter.com/shuding_/status/1580914103744221184