Hacker News new | ask | show | jobs
by xnyanta 1091 days ago
Sounds to me like CVE scanners aren't doing a great job if they can't pick up a nodejs installation from the official nodejs image distribution. Just looking at package manager metadata effectively won't give you the full picture.