There is something that have been bothering me for past few months, and resulted in me archiving node-ip repo on github: https://github.com/advisories/GHSA-78xj-cgh5-2h22
Someone filed a dubious CVE about my npm package, and then I started getting messages from all people getting warnings from `npm audit`.
I just posted a comment on the advisory issue https://github.com/github/advisory-database/pull/3504#issuecomment-2189530624 asking to remove it, but looking at dicer's advisory https://github.com/advisories/GHSA-wm7h-9275-46v2 I see that there might be a larger pattern in place?
/1
@indutny so does that mean you'd be unarchiving the node-ip repo or? I'm guessing it still needs the private vulnerability reporting enabled?
@indutny amazing, thanks!