Am 24.11.2021 um 18:14 schrieb Alexander Kanavin:
On Wed, 24 Nov 2021 at 18:11, Stefan Herbrechtsmeier <stefan.herbrechtsmeier-...@weidmueller.com <mailto:stefan.herbrechtsmeier-...@weidmueller.com>> wrote:


     > and shouldn't the tarball be fixed instead?

    How should we fix a tarball from npmjs.com <http://npmjs.com>?


By submitting a bug report or (better) a patch to the maintainers of the tarball?

The package is only an example and fixed on the fly by npm install.

The world is different in the npm ecosystem. The package is 2 years old, have no maintainer, no repository and 4k downloads per week. Furthermore you have to convince your dependencies to update their dependencies after you have fix a package.

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#158733): 
https://lists.openembedded.org/g/openembedded-core/message/158733
Mute This Topic: https://lists.openembedded.org/mt/87282285/21656
Group Owner: openembedded-core+ow...@lists.openembedded.org
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to