Hacker News new | ask | show | jobs
by bugglebeetle 1071 days ago
Indeed, the maintainer has commented on this very post that more work than simply tagging a release is involved with fixing, as well as that the CVE impact on their repo is bogus because they’re not actually affected by it.