As part of our security strengthening efforts: - Packages *must* be pinned to a version (we should have tooling to enforce this) and lockfiles are a must. - npm should use flag —frozen-lockfile