There is something that have been bothering me for past few months, and resulted in me archiving node-ip repo on github: https://github.com/advisories/GHSA-78xj-cgh5-2h22
Someone filed a dubious CVE about my npm package, and then I started getting messages from all people getting warnings from `npm audit`.
I just posted a comment on the advisory issue https://github.com/github/advisory-database/pull/3504#issuecomment-2189530624 asking to remove it, but looking at dicer's advisory https://github.com/advisories/GHSA-wm7h-9275-46v2 I see that there might be a larger pattern in place?
/1
@indutny if you want, I could help dispute and hopefully revoke the CVE
it's bogus that maintainers need to do this labor
@eslerm this would be awesome. Thank you so much!
@indutny great, I'll send an email
I'm on vacation this week, but can get the ball rolling over the weekend