Hacker News new | ask | show | jobs
by tutuca 1809 days ago
Excellent rundown of many problems I've encountered in recent versions of npm and node.

I've never ever got `audit fix` or `audit fix --force` to solve any of the mentioned vulnerabilities. Ever. I even relied on downloading every dependency one by one to find that there where other offending packages. I just gave up.

It's really useless and deceptive.