logoalt Hacker News

yreadyesterday at 10:28 PM2 repliesview on HN

Were there not enough eyes on React Server Components before the patches from last week?


Replies

Invizyesterday at 10:40 PM

have you seen the code of next.js? its completely impenetrable, and the packages have legacy versions of the same files coexisting, it's like huge hairball

manfretoday at 12:31 AM

I've noticed a pattern in the security reports for a project I'm involved in. After a CVE is released, for the next month or so there will likely be additional reports targeting the same (or similar) areas of the framework. There is definitely a competitive spirit amongst security researchers as they try to get more CVEs credited to them (and potentially bounties).