|
|
|
|
|
by jamesfinlayson
38 days ago
|
|
Yeah I completely understand their intent, but I might get 30 vulnerabilities across a multiple repos flagged in a week. It is already tedious to check them all and assess if they're worth worrying about let alone having to update them. These are 99% Javascript though - I suspect other ecosystems are much more manageable. |
|
Just updating everything is probably easier than assessing if it's possible to trigger an exploit with the way you use the package.