3 ms·
Who's actually audited all that? I'm sure it's insufficient but you asked who audits all that (re: npm) well, apparently somebody. https://docs.npmjs.com/cli/
by ryanmarsh 6y ago
Who's actually audited all that?
I'm sure it's insufficient but you asked who audits all that (re: npm) well, apparently somebody.
https://docs.npmjs.com/cli/v7/commands/npm-audit https://docs.npmjs.com/cli/v7/commands/npm-audit
The audit command submits a description of the dependencies configured in your project to your default registry and asks for a report of known vulnerabilities. If any vulnerabilities are found, then the impact and appropriate remediation will be calculated. If the fix argument is provided, then remediations will be applied to the package tree.
- jhardy54 6y agoThis provides a list of well-known vulnerabilities, it doesn't actually audit the source code to find unknown vulnerabilities.