Skip to content

Suggest ignoring a vulnerability by the package maintainer #386

@naugtur

Description

@naugtur

In a discussion of this: npm/rfcs#18
@wesleytodd suggested I bring it up here to collect feedback on the feature itself, but mostly to ask one thing:

If this can be leveraged for the package maintainers to declare a vulnerability in their own dependency does not affect the security of the package. And if so - how would you want to indicate that as opposed to ignoring the issue for your internal needs of stopping the CI from failing while there's no fix to update to.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions