logoalt Hacker News

themanmarantoday at 2:56 AM1 replyview on HN

Seriously. We got 116 github dependabot alerts this week. Half of them for dev dependencies.


Replies

jamesfinlaysontoday at 3:55 AM

I tried to raise that with my internal security team recently - don't clutter my vulnerability dashboard with issues in dev dependencies. They somewhat rightly pointed out that malware needs to be dealt even if it's a dev dependency. So my suggestion went nowhere because I guess we can't filter by type of vulnerability.

show 3 replies