alex opened this issue 10 months ago · 1 comments
Currently there's no way (AFAICT) to hash pin dependencies. For fully secure build envs, it'd be good if there was a flag that provided this behavior.
Quasi-duplicate of #292?