Replies: 2 comments 2 replies
-
That's normal. That's just npm packages. |
Beta Was this translation helpful? Give feedback.
-
I guess it's just generally concerning as a development ecosystem/platform that there can be so many unfixed vulnerabilities. I suppose we can assume (can we?) that none of these vulnerabilities are first-level dependencies (i.e. packages that this package depends on directly) that are not fully up-to-date with their upstream releases? It would be nice if the tool produced a graph of the dependency chains that have all of the vulnerabilities so that one can at least get a visual picture of how bad the problem is. |
Beta Was this translation helpful? Give feedback.
-
Just attempted to install for the first time, and I'm building from source. Is this amount of deprecated packages and vulnerabilities normal?
Beta Was this translation helpful? Give feedback.
All reactions