Source code
Code quality
Releases
Mixed package managers
Part of the Dependency supply chain check · fix arrives as a pull request
What it is
The repository contains lockfiles from more than one package manager — for example both package-lock.json and pnpm-lock.yaml.
Why it matters
Different tools resolve to different trees, so what CI builds depends on which command ran. The stale lockfile also keeps being updated by whoever uses that tool, which makes the disagreement permanent.
How to fix it
Pick one package manager, delete the other lockfiles, and declare the choice in packageManager so tooling and contributors follow it automatically.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.