Hacker News new | ask | show | jobs
by gherkinnn 1797 days ago
Here's some information on these "vulnerabilities": https://overreacted.io/npm-audit-broken-by-design/

As far as I'm concerned, there's no need for Dependabot to create PRs. The notifications in the security tab are enough. Mark the unnecessary ones as benign.

2 comments

The PRs are really helpful when you do actually want to update.
You can have Dependabot create a PR by hitting a button somewhere in the vulnerability details.
And here's the HN discussion on that thought-provoking post:

https://news.ycombinator.com/item?id=27761334