• False
    • None
    • False

      To get closer to prod sec and legal requirements, we should move from get-sources.sh -> asset*.gz file for the node dependencies, and instead use cachito w/ container.yaml configuration to fetch sources, then build the sources inside a Docker context, letting cachito find the dependencies in yarn.lock / package.json.

      See notes in CRW-3102 for how to move to using cachit o w/ yarn.

              mkuznets Mykhailo Kuznietsov
              nickboldt Nick Boldt
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: