← Back to context

Comment by patates

3 months ago

aren't these already nuked and show up in the "npm audit" command?

Annoyingly, npm audit relies on github's advisory DB, which is currently incorrectly flagging all versions of these packages, not just the compromised ones.

https://github.com/github/advisory-database/issues/6098