• tourist@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    13 days ago

    arbitrary npm package:

    • last updated 4 years ago
    • sole developer legit dead and buried
    • 47 dependencies
    • 608 critical vulnerabilities
    • condemned by the United Nations

    Still has 7 million weekly downloads