Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Update the hashing algorithm used for the
package-lock.json
checksum in the CI from MD5 to SHA512 - the same algorithm used by npm for the integrity check in thepackage-lock.json
file itself.My motivation for doing this is that MD5 is considered an insecure hash algorithm nowadays (ref. the MD5 Wikipedia page or RFC 6151). I do not intend to start a discussion on whether that's relevant in this particular case. I believe that regardless of ones point of view on the matter, upgrading to SHA512 is harmless (considering that this project is already using SHA512 through the lockfile).