NPM lockfiles can be a security blindspot for injecting malicious modules in PRs | Hacker News Reader