|
|
|
|
|
by mbesto
1814 days ago
|
|
> this “vulnerability” is absurd in this context Yes that's exactly the point. The audit tool has no awareness of the context and nor do the people who create severities. If severities were absolute then there would be no reason for anyone to review them. You would simply upgrade your libraries and be done with it, but that can't always be achieved nor may make business sense. I do agree with the author's note about providing a better way to provide feedback on severity reviews. npm audit is better than no npm audit...telling people it's broken by design is going to discourage them from using it completely. smh. |
|