You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In a discussion of this: npm/rfcs#18 @wesleytodd suggested I bring it up here to collect feedback on the feature itself, but mostly to ask one thing:
If this can be leveraged for the package maintainers to declare a vulnerability in their own dependency does not affect the security of the package. And if so - how would you want to indicate that as opposed to ignoring the issue for your internal needs of stopping the CI from failing while there's no fix to update to.
darcyclarke, wesleytodd, styfle, lirantal, thescientist13 and 1 more