So, um, how do I do the NPM equivalent of

$ cargo install --locked mergiraf

Let’s say I want to install https://www.npmjs.com/package/@google/gemini-cli — how do I prevent npm install from fetching malware-ridden dependencies that got published today, and instead have it used the locked version that the maintainers of gemini-cli have verified?

#npm #nodejs #javascript

0

If you have a fediverse account, you can quote this note from your own instance. Search https://genserver.social/objects/d1111754-5cfd-46cf-93a3-51ecf679ec1e on your instance and quote it. (Note that quoting is not supported in Mastodon.)