Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
To limit supply-chain attack vectors I'm trying to absorb and consolidate all
pg-*
libraries depended on into this repo so it can be versioned in lock-step and there are no transitive dependencies (exceptdevDependencies
) outside of things in this repo. Longer term (I have a TODO comment about it in the code already) I want to remove pg-pass as a dependency and have it something someone can install optionally. It was added before the.password
connection param could be made a function for inversion of control. Now that its possible to do whatever you want async to get the password, pg-pass eventually should be not included. In the mean time its a breaking change to remove it and adding pacakges to the monorepo is pretty easy.