For example, I noticed there're two jsonc related dependencies:
The one in the devDependencies was published 5 years ago, and maintained by 1 developer.
I know it's not been used in the source code yet, but I'm curious about how the supply chain security works there.
Thanks :)