Hacker News new | ask | show | jobs
by bjornstar 1695 days ago
create-react-app made their own security problems by bringing in the entire world, npm audit just makes that clear.

npm itself having vulnerabilities is a more serious problem and it's not clear that they're taking it seriously.