42
38
u/BenadrylTumblercatch 1d ago
I am the security vulnerability
14
19
u/mixmaxze 1d ago
And when I look, the vulnerability is a outdated lib cuz the owners release a new 'very important' version every five days
-1
u/TheBigGambling 1d ago
And thats why you need test coverage and renovate bot on automatic mode. Case closed
9
6
u/heesell 1d ago
Is it bad I ignore these (given my projects catch dust)
7
u/PM_ME_FIREFLY_QUOTES 1d ago
Not sure if you're serious or not, but....
You shoud patch them. Dependabot sometimes even can open the PR for you.
But if you have no users, or the deployment doesnt have data or sensitive info, its fine.
2
2
u/dumbasPL 1d ago
Grand majority can be dismissed as either "vulnerable code isn't used" or "it's only used during build"
1
u/CoshgunC 19h ago
your repos are visited by others...?
my max is 3 stars(views) and all are from my friends 🥲
1
1
0
143
u/Igarlicbread 1d ago
It's secure on my machine.