Please Pin github dependency version to a commit hash
envgap__TooTallNate__proxy-agents-387
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
4e922b55afcbd4b45b3e667ffad1d18ca58d1dfe- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
TooTallNate/proxy-agents #387 · read the original issue
The current published version of `socks-proxy-agent` includes this in its devDependencies: `"socksv5": "github:TooTallNate/socksv5#fix/dstSock-close-event"` If this dependency needs to reference github instead of a published version, it should reference a commit hash instead of a branch, so that the branch could not be updated in a supply chain attack of the dependency. This is low-risk because it's just a devDependency, but would be best to fix.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]