What is the policy for 3rd party one-line node modules? #16223
Unanswered
constup-foss
asked this question in
Q&A
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Hi,
I've come across a one-line module installed as a dependency of
jest-docblock. I generally treat one-line modules as a potential future vector of attack and a security risk, but don't know what is your policy. Should I report it as an issue or ignore it?Thanks.
All reactions