|
|
|
|
|
by nfm
125 days ago
|
|
The number of ReDoS vulnerabilities we see in Dependabot alerts for NPM packages we’re only using in client code is absurd. I’d love a fix for this that was aware of whether the package is running on our backend or not. Client side ReDoS is not relevant to us at all. |
|
It's just a silly historical artifact that we treat DoS as special, imo.