npm install with no committed package-lock.json re-resolved semver ranges fresh on every deploy instead of pinning to bun.lock (the project's actual lockfile) — a supply-chain integrity gap flagged by automated commit review. Use bun, the frontend's real package manager, with --frozen-lockfile so deploys are reproducible. Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ |
||
|---|---|---|
| .. | ||
| pg-init | ||
| deploy.sh | ||
| nginx-bekend.loki-code.dev.conf | ||
| nginx-visual.loki-code.dev.conf | ||
| setup.sh | ||