rem’s avatarrem’s Twitter Archive—№ 76,082

  1. So bored and tired of "security exploits" being reported against my project when the reporter hasn't given any actual thought to what they're reporting, but instead relying on either code scanning or the npm audit report (which is mostly useless from experience).
    1. …in reply to @rem
      Over the last 5+ years, only once was there are real vulnerability (which required updating a dependency of nodemon). The rest, thus far, have been a waste of time (and nearly all copy-and-paste security reports).