-
Already had the
npm auditissue filed against my repo. And yup, there's no remediation advice, doesn't include the version affected, and the bottom line: deep dep had bundled vuln - nothing I can do, except refer on. I'm reminded of this remysharp.com/2017/12/08/learn-more-about-vulnerability-alerts