Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
remram
4y ago
0 comments
Share
This is not a vulnerability (ie. security bug) it's an attack (ie. malicious).
0 comments
default
newest
oldest
Vinnl
4y ago
It doesn't really matter how you call it; the problem is that there could be CVE's in your devDependencies that affect your production build, and pruning those dependencies after using them to create that build doesn't remove the risk.
j
/
k
navigate · click thread line to collapse