fix(security): For bun, enforce frozen lockfile. For yarn, strongly suggest using frozen lockfile. (#5508)

* Updated docs for security information.
This commit is contained in:
Joe Boccanfuso authored and GitHub committed 2025-10-24 16:48:35 -04:00
1 parent b517944cb5
commit 1009c60911
24 files changed
+69 -25

No files matched your search

@@ -13,7 +13,7 @@ COPY ./ /usr/src/app/
# Install node dependencies
RUN yarn config set workspaces-experimental true
RUN yarn install
RUN yarn install --frozen-lockfile
# Set the environment for the build
ENV APP_CONFIG=config/docker-nginx-dcm4chee-keycloak.js
@@ -16,7 +16,7 @@ COPY ./ /usr/src/app/
# Install node dependencies
RUN yarn config set workspaces-experimental true
RUN yarn install
RUN yarn install --frozen-lockfile
# Copy the rest of the application code
@@ -19,7 +19,7 @@ COPY ./ /usr/src/app/
# Install node dependencies
RUN yarn config set workspaces-experimental true
RUN yarn install
RUN yarn install --frozen-lockfile
# Copy the rest of the application code
@@ -16,7 +16,7 @@ COPY ./ /usr/src/app/
# Install node dependencies
RUN yarn config set workspaces-experimental true
RUN yarn install
RUN yarn install --frozen-lockfile
# Copy the rest of the application code
+1 -1
View File
@@ -80,7 +80,7 @@ In your cloned repository's root folder, run:
```js
// Restore dependencies
yarn install
yarn install --frozen-lockfile
// Stands up local server to host Viewer.
// Viewer connects to our public cloud PACS by default